Executive brief
Microsoft Open Management Infrastructure (OMI) contains a remote code execution vulnerability due to an authentication bypass. The flaw allows unauthenticated attackers to execute arbitrary code on affected systems via the management interface. This vulnerability is widely known as 'OMIGOD' and has been observed being exploited in the wild.
Affected products
- Microsoft Open Management Infrastructure (OMI)
- Microsoft Azure Automation State Configuration
- Microsoft Azure Automation Update Management
- Microsoft Azure Diagnostics (LAD)
- Microsoft Azure Security Center
- Microsoft Azure Sentinel
- Microsoft Azure Stack Hub
- Microsoft Container Monitoring Solution
- Microsoft Log Analytics Agent
- Microsoft System Center Operations Manager
Timeline
- 2021-09-15: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: Published date listed in advisory title