Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The 2024 vSphere plug-in vulnerabilities affect the deprecated VMware Enhanced Authentication Plug-in (EAP) installed on Windows workstations—not vCenter Server itself. Broadcom’s recommended mitigation is to uninstall both EAP components from administrative endpoints: the “VMware Enhanced Authentication Plug-in 6.7.0” browser/client and the “VMware Plug-in Service.” If you cannot remove them immediately, stop and disable the service.

What is vulnerable?

EAP was a Windows component for integrated sign-in—including Windows Integrated Authentication and smart-card sign-in—to vSphere management interfaces. The incident report says it was discontinued in March 2021 and was not included by default in vCenter Server, ESXi, or Cloud Foundation; administrators manually installed it on Windows workstations. That describes the reported deployment model, not the current inventory of any organization. Dark Reading’s February 21, 2024 report and Broadcom’s removal guidance identify the affected endpoint software.

Broadcom identifies two applications that make up EAP: the browser/client named “VMware Enhanced Authentication Plug-in 6.7.0” and the Windows service named “VMware Plug-in Service.” Look for both on Windows workstations used to administer vSphere; removing only one does not follow Broadcom’s recommendation to remove both.

What do CVE-2024-22245 and CVE-2024-22250 do?

CVE Issue described in the 2024 report Reported severity
CVE-2024-22245 Authentication relay: a malicious website could trigger an EAP authentication flow; if the user accepted the plug-in communication request, an attacker could relay Kerberos service tickets. CVSS 9.6, attributed to VMware in the 2024 disclosure and reported by Dark Reading.
CVE-2024-22250 Local session hijacking: an attacker with unprivileged local access to a Windows system could use readable EAP log data and wait for a privileged user’s EAP session. CVSS 7.8, attributed to VMware in the 2024 disclosure and reported by Dark Reading.

The prerequisites matter: the described relay scenario involves a user accepting a plug-in communication request, while the session-hijack scenario involves local access to the Windows system. These reports do not establish either flaw as an unauthenticated remote takeover of vCenter Server. The scores are historical figures from the 2024 disclosure, not a new severity assessment. Dark Reading reported no evidence of exploitation at that time; that statement does not establish exploitation status today.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How to remove the VMware Enhanced Authentication Plug-in

Use Broadcom’s official EAP removal article for the supported, command-level details that match your Windows platform and deployment. It lists Control Panel, the original installer, and PowerShell as removal routes.

  1. Find the endpoint components. On Windows workstations used for vSphere administration, check for both “VMware Enhanced Authentication Plug-in 6.7.0” and “VMware Plug-in Service.”
  2. Uninstall both applications. Use one of Broadcom’s listed routes—Control Panel, the original installer, or PowerShell—and verify that both components have been removed.
  3. If removal must wait, stop and disable the service. Broadcom instructs administrators to stop and disable the “VMware Plug-in Service” as an interim measure.
  4. If the service cannot be stopped or disabled, apply the documented network fallback. Broadcom’s article says to firewall inbound and outbound TCP traffic on port 8094 when service disablement is not possible. Confirm the rule’s scope and platform-specific details against the KB before applying it.

Broadcom also documents an optional vCenter SSO setting to remove the “Use Windows Session Authentication” checkbox. This changes the sign-in option presented to users; it is not a substitute for removing the endpoint components or disabling the service. The remediation described in the KB is not simply disabling a plug-in in a vSphere interface.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Is there an EAP patch?

The cited sources identify mitigation by removal, not a separate EAP security patch. Dark Reading reported that VMware chose removal as the mitigation because EAP had been discontinued. Consult Broadcom’s current KB for any later updates rather than assuming an EAP patch is available.

What should replace EAP sign-in?

Removing EAP does not require choosing a specific replacement identity provider. Dark Reading names Active Directory over LDAPS, ADFS, Okta, and Microsoft Entra ID as authentication alternatives. These are configuration choices, not immediate vulnerability fixes. Compare them against the vSphere versions you support, your existing directory and identity-provider architecture, migration and operational effort, and your authentication requirements before selecting an approach. The report does not rank these options or establish compatibility for every environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the 2024 disclosure establishes—and what it does not

Dark Reading’s February 21, 2024 account credits Ceri Coburn of Pen Test Partners with discovery and responsible disclosure. It describes VMware’s characterization of the issues as an authentication relay vulnerability and a session-hijack vulnerability, and says the vendor’s mitigation was removal of the deprecated plug-in. The report’s exploitation-status statement applies to the time of publication, not to October 2026 or any later date.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.