CVE-2021-38649KEV · OVERDUE

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

High · published September 15, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 7.0. It is confirmed in active exploitation. It sits in the 85.9th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
7.0
EPSS
3%
Percentile
85.9
In the wild
Confirmed
What it is

⚡ An elevation of privilege vulnerability in Open Management Infrastructure (OMI) could let attackers take full control with just a few crafty commands! Think of OMI like a hotel with a master key system. If a mischievous guest somehow obtains the master key, they could access any room, snoop through personal belongings, or even change reservations without a trace! This vulnerability is absolutely devastating! An attacker could exploit it to execute arbitrary code with elevated privileges, effectively turning them into a superuser. The results could lead to unauthorized access to sensitive data, system manipulation, and even a complete takeover of affected servers.

Put simply

Think of OMI like a hotel with a master key system. If a mischievous guest somehow obtains the master key, they could access any room, snoop through personal belongings, or even change reservations without a trace! The vulnerability arises from improper input validation, allowing an attacker who has access to the OMI service to execute harmful commands that escalate their privileges, bypassing normal security controls.

What to do

This vulnerability is absolutely devastating! An attacker could exploit it to execute arbitrary code with elevated privileges, effectively turning them into a superuser. The results could lead to unauthorized access to sensitive data, system manipulation, and even a complete takeover of affected servers. To protect your systems, update OMI to the latest patched version immediately. It's also wise to audit permissions and limit access to the OMI service only to trusted users. Don't forget to apply additional security controls where possible! You've got this! Take action now and secure your environment like the hero you are! 🦸

The record
Technical detail
CVSS v3.1
7.0 · HIGH
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.02887 · 85.9th percentile
Published
2021-09-15T16:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (11)
ProductVersionsFixed in
microsoft/azure_automation_state_configurationall versions
microsoft/azure_automation_update_managementall versions
microsoft/azure_diagnostics_\(lad\)all versions
microsoft/azure_open_management_infrastructureall versions
microsoft/azure_security_centerall versions
microsoft/azure_sentinelall versions
microsoft/azure_stack_huball versions
microsoft/container_monitoring_solutionall versions
microsoft/log_analytics_agentall versions
microsoft/open_management_infrastructure< 1.6.8-11.6.8-1
microsoft/system_center_operations_managerall versions
References (3)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 15 SEP 11:24Z
    Open Management Infrastructure Elevation of Privilege Vulnerability
    cvelistv5