Open Management Infrastructure Elevation of Privilege Vulnerability
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HMicrosoft Azure Automation State Configuration
APPMicrosoftall versionsMicrosoft Azure Automation Update Management
APPMicrosoftall versionsMicrosoft Azure Diagnostics \(lad\)
APPMicrosoftall versionsMicrosoft Azure Open Management Infrastructure
APPMicrosoftall versionsMicrosoft Azure Security Center
APPMicrosoftall versionsMicrosoft Azure Sentinel
APPMicrosoftall versionsMicrosoft Azure Stack Hub
APPMicrosoftall versionsMicrosoft Container Monitoring Solution
APPMicrosoftall versionsMicrosoft Log Analytics Agent
APPMicrosoftall versionsMicrosoft Open Management Infrastructure
APPMicrosoft< 1.6.8-1Microsoft System Center Operations Manager
APPMicrosoftall versions
CISA KEV — detailsi
- Vendori
- Microsoft ↗
- Producti
- Open Management Infrastructure (OMI)
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- November 17, 2021(overdue)
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
⏰CISA DEADLINE: 17 listopada 2021
Related vulnerabilities
CVE-2021-38647CRITICAL9.8⚠ KEVsame product
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVE-2024-38220CRITICAL9.0PL ✓same product
Microsoft Azure Stack Hub — Elevation of Privilege (podatność krytyczna)
CVE-2024-38108CRITICAL9.3PL ✓same product
XSS/Spoofing w Microsoft Azure Stack Hub — krytyczna podatność
CVE-2024-21334CRITICAL9.8PL ✓same product
RCE w Open Management Infrastructure (OMI) — use-after-free
CVE-2021-38649HIGH7.0⚠ KEVsame product
Open Management Infrastructure Elevation of Privilege Vulnerability