# CVE-2024-22250

## Summary

- **CVE ID:** CVE-2024-22250
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-384
- **Published:** Feb 20, 2024
- **Last Modified:** Mar 13, 2026

## Description

Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system.

## Affected Products

- VMware — VMware Enhanced Authentication Plug-in (EAP) (All)

## References

- [CNA](https://www.vmware.com/security/advisories/VMSA-2024-0003.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.35%
- **EPSS Percentile:** 27.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._