Executive brief
Microsoft Open Management Infrastructure (OMI) contains a privilege escalation vulnerability that allows a local attacker to gain elevated permissions. The flaw is present in various Azure VM Management Extensions and monitoring agents that utilize the OMI framework.
Affected products
- Microsoft Open Management Infrastructure (OMI)
- Microsoft Azure Automation State Configuration
- Microsoft Azure Automation Update Management
- Microsoft Azure Diagnostics (LAD)
- Microsoft Azure Security Center
- Microsoft Azure Sentinel
- Microsoft Azure Stack Hub
- Microsoft Container Monitoring Solution
- Microsoft Log Analytics Agent
- Microsoft System Center Operations Manager
Timeline
- 2021-09-15: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild in advisory metadata