Junglewise Threat Intelligence

CVE-2021-38649: Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

CVE-2021-38649 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Open Management Infrastructure (Omi). Vendors: Microsoft.

Executive brief

Microsoft Open Management Infrastructure (OMI) contains an elevation of privilege vulnerability. An attacker with local access could exploit this flaw to gain elevated permissions on affected systems, including various Azure VM Management Extensions and monitoring tools.

Affected products

  • Microsoft Open Management Infrastructure (OMI)
  • Microsoft Azure Automation State Configuration
  • Microsoft Azure Automation Update Management
  • Microsoft Azure Diagnostics (LAD)
  • Microsoft Azure Security Center
  • Microsoft Azure Sentinel
  • Microsoft Azure Stack Hub
  • Microsoft Container Monitoring Solution
  • Microsoft Log Analytics Agent
  • Microsoft System Center Operations Manager

Timeline

  • 2021-09-15: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: other: Advisory publication date provided in report

Related threats