
VMware has come up with a warning to the users to uninstall the VMware Enhanced Authentication Plug-in (EAP) due to critical and high severity vulnerabilities.
The VMware EAP is a deprecated browser plugin that enables seamless single sign-on (SSO) to vSphere’s management interface from client workstations. It is an optional feature that stopped receiving support with the release of VMware vCenter Server 7.0.0u2 in March 2021.
The vulnerability tracked as CVE-2024-22245, with a CVSS score of 9.6 could allow a remote attacker to perform an arbitrary authentication relay attack by tricking a user with the plugin installed into visiting a malicious website. The arbitrary authentication relay bug allows attackers to communicate with the VMware EAP using WebSocket commands on a malicious website and request arbitrary Kerberos tickets on behalf of a victim.
These tickets can be requested for any Active Directory Service Principal Names (SPNs), allowing the attacker to access any service within the victim’s Active Directory network. When a victim visits a malicious website and a ticket request is made, the browser will notify the user that the website is attempting to communicate with the VMware EAP. The ticket is relayed if the user clicks the popup option to allow access.
The vulnerability is believed to have been exploited in the wild, VMware said in a FAQ regarding its advisory. No patch available for VMWare plugin vulnerabilities, uninstall required. VMware has provided instructions for users to uninstall the VMware EAP, which requires the removal of two components – the in-browser plugin itself and the Windows service “VMware Plug-in Service.”
Users can uninstall the vulnerable features from the Windows Control Panel, in the original program installers, or by running PowerShell commands. VMware also provides instructions for disabling the Windows service if it’s not possible to uninstall, and for firewalling traffic from the plugin if no other options are available.
A link to install VMware EAP is still present on the vSphere Client login page but is planned to be removed in a future update, according to the VMware FAQ. Despite being deprecated in 2021, the VMware EAP remains the only option for SSO authentication for vSphere 7, which will remain supported until April 2025.
The latest platform version, vSphere 8, offers additional authentication methods, including via the Lightweight Directory Access Protocol over SSL (LDAPS), Microsoft Active Directory Federation Services (ADFS), Okta and Microsoft Entra ID, according to VMware.
Users do not need to patch VMware vCenter Server, VMware ESXi, or VMware Cloud Foundation to protect against CVE-2024-22245.


