{"id":2565,"date":"2024-02-21T15:22:14","date_gmt":"2024-02-21T15:22:14","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/critical-vulnerability-vmware-vsphere-plugin-session-hijacking"},"modified":"2024-02-21T15:22:14","modified_gmt":"2024-02-21T15:22:14","slug":"critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/02\/21\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking\/","title":{"rendered":"Critical Vulnerability in VMware vSphere Plug-in Allows Session Hijacking"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt0b78ebd48da38927\/655e08ffab1c33040a3a9efb\/cloud_security_Bob-Venezia-Alamy-Stock-Photo.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">VMware is urging network administrators to remove an out-of-date plug-in for its VSphere, which has two flaws \u2014 one of them critical \u2014 that can allow attackers with access to a Windows client system to hijack cloud computing sessions.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">VMware this week released a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2024-0003.html\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">security advisory<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> addressing the flaws \u2014 one tracked as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-22245\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">CVE-2024-22245<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, with a severity rating of 9.6, and one tracked as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-22250\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">CVE-2024-22250<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, with a severity rating of 7.8 \u2014 which are found in VMware Enhanced Authentication Plug-in (EAP). EAP makes it easy to sign in to vSphere&#8217;s management interfaces via integrated Windows Authentication and Windows-based smart-card functionality on Windows client systems, according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/vulnera.com\/newswire\/vmware-calls-for-removal-of-outdated-vulnerable-authentication-plugin\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">a blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by vulnerability-detection security firm Vulnera.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CVE-2024-22245 is an arbitrary authentication relay <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/vmware-issues-alarming-security-advisory\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">vulnerability<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, while CVE-2024-22250 is a session-hijack flaw, according to VMware. Threat actors can exploit CVE-2024-22245 &#8220;to relay Kerberos service tickets and seize control of privileged EAP sessions,&#8221; while CVE-2024-22250 can be used by a malicious actor with unprivileged local access to a Windows OS to &#8220;hijack a privileged EAP session when initiated by a privileged domain user on the same system,&#8221; according to Vulnera.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The company credited Ceri Coburn at Pen Test Partners for discovering the vulnerabilities and responsibly disclosing them, which according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.pentestpartners.com\/security-blog\/no-fix-krbrelay-vmware-style\/\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">a blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> published today by Pen Test was done on Oct. 17. VMware did not offer an explanation for why it took several months to release a vulnerability advisory and mitigation.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"How the Flaws Work\">How the Flaws Work<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">EAP creates a seamless login experience for the Web console of vSphere, VMware&#8217;s virtualization platform that creates aggregated cloud computing infrastructures composed of CPU, storage, and networking resources out of data center environments.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Digging further into the flaws, the critical CVE-2024-22245 is a Kerberos relay vulnerability that allows a malicious website to trigger the same authentication flow that the typical vCenter login page uses, according to Pen Test&#8217;s blog post. In this scenario, EAP will notify the end user that a website is trying to communicate with the plug-in, which the user must accept; however, an unsuspecting user who accepts the request is then vulnerable to attack.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;A malicious website can then request Kerberos tickets for any service within the victim&#8217;s Active Directory network as the victim user,&#8221; according to Pen Test&#8217;s posting.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, CVE-2024-22250 is related to weak permissions set on the VMware EAP log file stored within the ProgramData folder. Because the log file is configured to allow any local user to read it, an attacker can set up an automated script to read from the log file and listen for new session IDs, according to Pen Test.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Once a new session ID is logged, an attacker can request arbitrary service tickets on behalf of users within other sessions, and then access Kerberos-related services configured within the Active Directory network as the hijacked user from the other session.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Unlike the first CVE, this one does not require an interaction with a suspicious website,&#8221; according to Pen Test.&nbsp;&#8220;The attacker simply waits for the authentication to occur to a legitimate vCenter login page, [then hijacks] the user session.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Remove Vulnerable Plug-in Now\">Remove Vulnerable Plug-in Now<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">VMware has responded not by patching EAP \u2014 which was discontinued by VMware in March 2021 with the launch of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/docs.vmware.com\/en\/VMware-vSphere\/7.0\/rn\/vsphere-vcenter-server-702-release-notes.html\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">vCenter Server 7.0 Update 2<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> \u2014 but it&#8217;s giving administrators step-by-step instructions in an <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/kb.vmware.com\/s\/article\/96442\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">article on its website<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that explains how it can be removed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So far, there is no evidence that the flaws have been exploited by threat actors, according to VMware. However, historically, threat actors <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/chinese-spies-exploited-critical-vmware-bug-2-years\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">pounce on VMware flaws<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> because of the opportunity they present to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/dell-credentials-bug-vmware-environments-takeover\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">compromise a cloud environment<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and thus provide access to myriad enterprise resources and data. For instance, despite being patched, attackers pummeled a previously disclosed <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/attackers-can-exploit-flaw-in-vmware-esxi-hypervisor-in-multiple-ways\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">VMware ESXi hypervisor flaw<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that was exploitable in many ways for years. Thus, mitigating risk by removing EAP as soon as possible is crucial, VMware and security researchers alike said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Pen Test deemed the move to forgo patching &#8220;unfortunate,&#8221; as the vSphere 7 product line that uses the plug-in remains supported until April 2025.&nbsp;But in some good news for VMware customers, systems using vSphere will not have EAP installed by default, nor is the plug-in included in VMware&#8217;s vCenter Server, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/abyss-locker-ransomware-vmware-esxi-servers\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">ESXi<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, or Cloud Foundation products. Administrators have to manually install EAP on Windows workstations used for administrative tasks to enable direct login when using the VMware vSphere Client via a Web browser, according to Vulnera.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">VMware has instructed clients using EAP to remove both entities that comprise the plug-in (the in-browser plug-in\/client &#8220;VMware Enhanced Authentication Plug-in 6.7.0&#8221; and the Windows service &#8220;VMware Plug-in Service&#8221;). If this is not possible, administrators also can disable the Windows service.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">VMware presents three options for removing each of these components from either the control panel or the installer, or by using PowerShell, according to its instructions. The company also presented safer alternatives to using EAP, including VMware vSphere 8 authentication methods such as Active Directory over LDAPS, Microsoft Active Directory Federation Services (ADFS), Okta, and Microsoft Entra ID (formerly Azure AD).<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/critical-vulnerability-vmware-vsphere-plugin-session-hijacking\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>VMware is urging network administrators to remove an out-of-date plug-in<\/p>\n","protected":false},"author":12,"featured_media":2566,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2565","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?fit=1200%2C687&ssl=1",1200,687,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?fit=300%2C172&ssl=1",300,172,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?fit=640%2C367&ssl=1",640,367,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?fit=640%2C366&ssl=1",640,366,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?fit=1200%2C687&ssl=1",1200,687,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?fit=1200%2C687&ssl=1",1200,687,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?fit=1024%2C586&ssl=1",1024,586,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/02\/critical-vulnerability-in-vmware-vsphere-plug-in-allows-session-hijacking.jpg?fit=1200%2C687&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2565","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2565"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2565\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2566"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}