CVE-2021-38645KEV · OVERDUE

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

High · published September 15, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 7.8. It is confirmed in active exploitation. It sits in the 85.1th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
7.8
EPSS
3%
Percentile
85.1
In the wild
Confirmed
What it is

⚡ An elevation of privilege vulnerability in Open Management Infrastructure (OMI) is like having the keys to the server room but only needing a guest badge to get in! 🚪🔑 Think of OMI as a hotel with a fancy security system, where guests can wander in with simple room keys but can access restricted areas, like the staff-only kitchens or the vault! If an attacker exploits this vulnerability, they could gain access to sensitive information, change settings, or even take complete control of the system—an absolute nightmare for any organization! This means everything from sensitive data leaks to unauthorized actions can be performed without detection.

Put simply

Think of OMI as a hotel with a fancy security system, where guests can wander in with simple room keys but can access restricted areas, like the staff-only kitchens or the vault! This vulnerability allows attackers to execute code with elevated privileges due to inadequate authorization checks in the Open Management Infrastructure, enabling unauthorized access to system-level resources.

What to do

If an attacker exploits this vulnerability, they could gain access to sensitive information, change settings, or even take complete control of the system—an absolute nightmare for any organization! This means everything from sensitive data leaks to unauthorized actions can be performed without detection. To secure your systems, apply the latest patches provided by your vendor immediately. Additionally, review your OMI configurations and limit access to essential personnel only. Don't forget to monitor any unusual activity to catch potential exploitation early! You've got this! Stay proactive, follow these steps, and you'll have your systems fortified in no time! 🛡️

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.02727 · 85.1th percentile
Published
2021-09-15T16:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (10)
ProductVersionsFixed in
microsoft/azure_automation_state_configurationall versions
microsoft/azure_automation_update_managementall versions
microsoft/azure_diagnostics_\(lad\)all versions
microsoft/azure_security_centerall versions
microsoft/azure_sentinelall versions
microsoft/azure_stack_huball versions
microsoft/container_monitoring_solutionall versions
microsoft/log_analytics_agentall versions
microsoft/open_management_infrastructure< 1.6.8-11.6.8-1
microsoft/system_center_operations_managerall versions
References (3)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 15 SEP 11:24Z
    Open Management Infrastructure Elevation of Privilege Vulnerability
    cvelistv5