Junglewise Threat Intelligence

CVE-2021-38647: Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CVE-2021-38647 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Open Management Infrastructure (Omi). Vendors: Microsoft.

Executive brief

Microsoft Open Management Infrastructure (OMI) contains a remote code execution vulnerability due to an authentication bypass. The flaw allows unauthenticated attackers to execute arbitrary code on affected systems via the management interface. This vulnerability is widely known as 'OMIGOD' and has been observed being exploited in the wild.

Affected products

  • Microsoft Open Management Infrastructure (OMI)
  • Microsoft Azure Automation State Configuration
  • Microsoft Azure Automation Update Management
  • Microsoft Azure Diagnostics (LAD)
  • Microsoft Azure Security Center
  • Microsoft Azure Sentinel
  • Microsoft Azure Stack Hub
  • Microsoft Container Monitoring Solution
  • Microsoft Log Analytics Agent
  • Microsoft System Center Operations Manager

Timeline

  • 2021-09-15: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: Published date listed in advisory title

Related threats