CVE-2021-38647KEV · OVERDUE

Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Critical · published September 15, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 A remote code execution vulnerability in Open Management Infrastructure is causing quite the stir! Just one malicious request is all it takes to unleash chaos! 🔥 Think of Open Management Infrastructure like an unattended restaurant kitchen, where anyone can walk in and cook whatever they want without anyone checking their credentials. This vulnerability lets attackers bypass all the usual door locks and safety protocols, making it dangerously easy for them to wreak havoc. With this flaw, an attacker could potentially gain complete control over your system—executing any command they choose, which can lead to data theft, unauthorized access, or even total system compromise. It’s absolutely devastating if this vulnerability is exploited, as it could lead to significant security breaches.

Put simply

Think of Open Management Infrastructure like an unattended restaurant kitchen, where anyone can walk in and cook whatever they want without anyone checking their credentials. This vulnerability lets attackers bypass all the usual door locks and safety protocols, making it dangerously easy for them to wreak havoc. CVE-2021-38647 allows remote attackers to execute arbitrary code via crafted requests to the Open Management Infrastructure service. This means the service trusts and executes any code that an attacker sends, effectively giving them the keys to the kingdom.

What to do

With this flaw, an attacker could potentially gain complete control over your system—executing any command they choose, which can lead to data theft, unauthorized access, or even total system compromise. It’s absolutely devastating if this vulnerability is exploited, as it could lead to significant security breaches. Immediately patch your systems to the latest version, as the vulnerability is known to be exploited. Ensure that your firewall settings are restrictive and monitor your network for any suspicious activity. Regularly update your infrastructure to minimize the risk of such vulnerabilities in the future. You’ve got this! Follow these steps and you’ll be locking down your systems in no time! 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.99933 · 100.0th percentile
Published
2021-09-15T16:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (10)
ProductVersionsFixed in
microsoft/azure_automation_state_configurationall versions
microsoft/azure_automation_update_managementall versions
microsoft/azure_diagnostics_\(lad\)all versions
microsoft/azure_security_centerall versions
microsoft/azure_sentinelall versions
microsoft/azure_stack_huball versions
microsoft/container_monitoring_solutionall versions
microsoft/log_analytics_agentall versions
microsoft/open_management_infrastructure< 1.6.8-11.6.8-1
microsoft/system_center_operations_managerall versions
References (4)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 15 SEP 11:24Z
    Open Management Infrastructure Remote Code Execution Vulnerability
    cvelistv5