Junglewise Threat Intelligence

CVE-2021-38645: Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

CVE-2021-38645 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Open Management Infrastructure (Omi). Vendors: Microsoft.

Executive brief

Microsoft Open Management Infrastructure (OMI) contains a privilege escalation vulnerability that allows a local attacker to gain elevated permissions. The vulnerability impacts various Azure VM Management Extensions and System Center products that utilize the OMI framework.

Affected products

  • Microsoft Open Management Infrastructure (OMI)
  • Microsoft Azure Automation State Configuration
  • Microsoft Azure Automation Update Management
  • Microsoft Azure Diagnostics (LAD)
  • Microsoft Azure Security Center
  • Microsoft Azure Sentinel
  • Microsoft Azure Stack Hub
  • Microsoft Container Monitoring Solution
  • Microsoft Log Analytics Agent
  • Microsoft System Center Operations Manager

Timeline

  • 2021-09-15: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: Published date per advisory title

Related threats