VYPR

Enhanced Authentication Plug-in

by VMware

CVEs (2)

  • CVE-2024-22245CriFeb 20, 2024
    risk 0.62cvss 9.6epss 0.01

    Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service…

  • CVE-2024-22250HigFeb 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system.