---
title: "VMware Alert: Uninstall EAP Now – Critical Flaw Puts Active Directory at Risk"
description: "Urgent warning for VMware users: Uninstall the deprecated Enhanced Authentication Plugin (EAP) immediately due to a critical security flaw. The vulnerability, tracked as CVE-2024-22245, could put Active Directory at risk. Learn more!"
image: https://blog.oitc.ca/hubfs/Imported_Blog_Media/vmware.jpg
---

[Skip to content](https://blog.oitc.ca/alerts/vmware-alert-uninstall-eap-now-critical-flaw-puts-active-directory-at-risk#main-content)

![Outsource IT Computing](https://blog.oitc.ca/hs-fs/hubfs/OITC%20Logo-1.png?width=1408&height=302&name=OITC%20Logo-1.png)Homepage

- [Services](https://oitc.ca/services)
- [Industries](https://oitc.ca/industries)
- Company
  
    - [Careers](https://oitc.ca/careers)
    - [About Us](https://oitc.ca/about)
    - [Solution Partners](https://oitc.ca/solution-partners)
    - [Community Support](https://oitc.ca/community-support)
- Resources
  
    - [Blog](https://blog.oitc.ca)
    - [Bill Payments](https://pay.oitc.ca/)
    - [VoIP 911](https://oitc.ca/v911/)
    - [Client Portal](https://portal.oitc.ca/)

[Get started](https://oitc.ca/contact/)

- [Services](https://oitc.ca/services)
- [Industries](https://oitc.ca/industries)
- Company
  
    - [Careers](https://oitc.ca/careers)
    - [About Us](https://oitc.ca/about)
    - [Solution Partners](https://oitc.ca/solution-partners)
    - [Community Support](https://oitc.ca/community-support)
- Resources
  
    - [Blog](https://blog.oitc.ca)
    - [Bill Payments](https://pay.oitc.ca/)
    - [VoIP 911](https://oitc.ca/v911/)
    - [Client Portal](https://portal.oitc.ca/)

[Get started](https://oitc.ca/contact/)

![](https://blog.oitc.ca/hs-fs/hubfs/Imported_Blog_Media/vmware.jpg?width=728&height=380&name=vmware.jpg)

Alerts

# VMware Alert: Uninstall EAP Now – Critical Flaw Puts Active Directory at Risk

![Nathan Zych](https://7528315.fs1.hubspotusercontent-na1.net/hub/7528315/hubfs/raw_assets/public/mV0_d-cms-elevate-theme_hubspot/elevate/images/avatar-placeholder.jpg?width=48&height=48&name=avatar-placeholder.jpg)

 Nathan Zych

February 29, 2024

VMware has issued an urgent warning advising users to uninstall the deprecated Enhanced Authentication Plugin (EAP) due to the discovery of a critical security flaw. The vulnerability, tracked as CVE-2024-22245 with a CVSS score of 9.6, has been identified as an arbitrary authentication relay bug.

According to VMware, a malicious actor could exploit the flaw to trick a target domain user with EAP installed in their web browser into requesting and relaying authentication credentials from the user’s browser to EAP-enabled web servers, potentially putting Active Directory at risk.

It is crucial for all VMware users to immediately uninstall EAP to mitigate the security risk. The latest security alert can be found [here](https://thehackernews.com/2024/02/vmware-alert-uninstall-eap-now-critical.html).

[![GET UNLIMITED REMOTE AND ONSITE BUSINESS IT SUPPORT FOR A FIXED FEE](https://blog.oitc.ca/hs-fs/hubfs/Imported_Blog_Media/MSP-B-Jul-10-2025-10-03-36-6550-PM.png?width=900&name=MSP-B-Jul-10-2025-10-03-36-6550-PM.png)](https://www.oitc.ca/contact/)

[Click here to contact Outsource IT](https://www.oitc.ca/contact/)

## Share this post

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fvmware-alert-uninstall-eap-now-critical-flaw-puts-active-directory-at-risk><https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fvmware-alert-uninstall-eap-now-critical-flaw-puts-active-directory-at-risk><https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fvmware-alert-uninstall-eap-now-critical-flaw-puts-active-directory-at-risk><https://pinterest.com/pin/create/button/?url=https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fvmware-alert-uninstall-eap-now-critical-flaw-puts-active-directory-at-risk>[mailto:https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fvmware-alert-uninstall-eap-now-critical-flaw-puts-active-directory-at-risk](mailto:https%3A%2F%2Fblog.oitc.ca%2Falerts%2Fvmware-alert-uninstall-eap-now-critical-flaw-puts-active-directory-at-risk)

## Keep reading

### [Managed IT vs In-House IT: Why It’s Not Always an Either-Or Decision](https://blog.oitc.ca/managed-it-vs-in-house-it-why-its-not-always-an-either-or-decision)

### [Blog 10 Signs You’ve Outgrown Your Current IT Provider](https://blog.oitc.ca/10-signs-youve-outgrown-your-current-it-provider)

[![OITC Logo-1](https://blog.oitc.ca/hs-fs/hubfs/OITC%20Logo-1.png?width=300&height=64&name=OITC%20Logo-1.png "OITC Logo-1")](https://oitc.ca)

<https://www.linkedin.com/organization/1598823/><https://www.facebook.com/outsourceitcomputing/><https://x.com/oitc_ca>

---

[Privacy Policy](https://oitc.ca/privacy-policy/) · © 2025. All rights reserved.

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Nathan Zych",
    "url" : "https://blog.oitc.ca/author/nathan-zych"
  },
  "dateModified" : "2025-07-10T22:04:09.593Z",
  "datePublished" : "2024-02-29T11:26:56.000Z",
  "headline" : "VMware Alert: Uninstall EAP Now – Critical Flaw Puts Active Directory at Risk",
  "mainEntityOfPage" : {
    "@id" : "https://blog.oitc.ca/alerts/vmware-alert-uninstall-eap-now-critical-flaw-puts-active-directory-at-risk",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.oitc.ca/hubfs/OITC%20Logo-1.png"
    }
  }
}
```