CVE-2021-38648KEV · OVERDUE

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

High · published September 15, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 7.8. It is confirmed in active exploitation. It sits in the 95.7th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
7.8
EPSS
11%
Percentile
95.7
In the wild
Confirmed
What it is

🚨 This vulnerability lets an attacker elevate privileges with just a single command! 🔥 If you're using Open Management Infrastructure, it's time to pay attention. Think of it like a VIP pass at a concert — without authorization, someone could waltz backstage and access the green room, turning a fun event into a chaotic mess. This flaw allows unauthorized users to gain elevated privileges, navigating parts of the system they shouldn't see. The consequences could be absolutely devastating! An attacker could take complete control of the Open Management Infrastructure, allowing them to manipulate settings, access sensitive data, or even disrupt services altogether. This level of access is a dream come true for malicious actors with bad intentions!

Put simply

Think of it like a VIP pass at a concert — without authorization, someone could waltz backstage and access the green room, turning a fun event into a chaotic mess. This flaw allows unauthorized users to gain elevated privileges, navigating parts of the system they shouldn't see. CVE-2021-38648 is an elevation of privilege vulnerability in Open Management Infrastructure, where improper access controls allow attackers to execute commands with higher privileges than intended.

What to do

The consequences could be absolutely devastating! An attacker could take complete control of the Open Management Infrastructure, allowing them to manipulate settings, access sensitive data, or even disrupt services altogether. This level of access is a dream come true for malicious actors with bad intentions! To mitigate this risk, ensure you're running the patched version of Open Management Infrastructure that addresses this vulnerability. Immediately restrict access to sensitive management functions and audit user permissions to ensure that only authorized personnel have the necessary access. Don't forget to update any outdated systems! You've got this! By taking proactive measures now, you'll keep your systems secure and reduce the risk of exploitation. 🛡️

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.11424 · 95.7th percentile
Published
2021-09-15T16:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (11)
ProductVersionsFixed in
microsoft/azure_automation_state_configurationall versions
microsoft/azure_automation_update_managementall versions
microsoft/azure_diagnostics_\(lad\)all versions
microsoft/azure_open_management_infrastructureall versions
microsoft/azure_security_centerall versions
microsoft/azure_sentinelall versions
microsoft/azure_stack_huball versions
microsoft/container_monitoring_solutionall versions
microsoft/log_analytics_agentall versions
microsoft/open_management_infrastructure< 1.6.8-11.6.8-1
microsoft/system_center_operations_managerall versions
References (4)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 15 SEP 11:24Z
    Open Management Infrastructure Elevation of Privilege Vulnerability
    cvelistv5