HIGH🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2021-38648

CVSS 7.8v3.1pub. 2021-09-15upd. 2026-08-10

Open Management Infrastructure Elevation of Privilege Vulnerability

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Microsoft Azure Automation State Configuration

    APP
    Microsoft
    all versions
  • Microsoft Azure Automation Update Management

    APP
    Microsoft
    all versions
  • Microsoft Azure Diagnostics \(lad\)

    APP
    Microsoft
    all versions
  • Microsoft Azure Open Management Infrastructure

    APP
    Microsoft
    all versions
  • Microsoft Azure Security Center

    APP
    Microsoft
    all versions
  • Microsoft Azure Sentinel

    APP
    Microsoft
    all versions
  • Microsoft Azure Stack Hub

    APP
    Microsoft
    all versions
  • Microsoft Container Monitoring Solution

    APP
    Microsoft
    all versions
  • Microsoft Log Analytics Agent

    APP
    Microsoft
    all versions
  • Microsoft Open Management Infrastructure

    APP
    Microsoft
    < 1.6.8-1
  • Microsoft System Center Operations Manager

    APP
    Microsoft
    all versions

CISA KEV — detailsi

Vendori
Microsoft
Producti
Open Management Infrastructure (OMI)
Added to KEVi
November 3, 2021
Remediation deadline (US Federal)i
November 17, 2021(overdue)
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 17 listopada 2021
CWE
References

Related vulnerabilities

CVE-2021-38647CRITICAL9.8⚠ KEVsame product

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CVE-2024-38220CRITICAL9.0PL ✓same product

Microsoft Azure Stack Hub — Elevation of Privilege (podatność krytyczna)

CVE-2024-38108CRITICAL9.3PL ✓same product

XSS/Spoofing w Microsoft Azure Stack Hub — krytyczna podatność

CVE-2024-21334CRITICAL9.8PL ✓same product

RCE w Open Management Infrastructure (OMI) — use-after-free

CVE-2021-38649HIGH7.0⚠ KEVsame product

Open Management Infrastructure Elevation of Privilege Vulnerability