ZeroHour

CVE-2021-38645

KEVmass1

Local Privilege Escalation in Microsoft Open Management Infrastructure (OMI)

CISA: Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p85
Published
()
KEV added
AI analysis

CVE-2021-38645 is an elevation of privilege vulnerability in Microsoft's Open Management Infrastructure (OMI), a management agent that Microsoft silently deploys on Azure Linux virtual machines through services such as Azure Security Center, Azure Sentinel, Azure Automation (State Configuration and Update Management), Azure Diagnostics (LAD), the Log Analytics agent, and Container Monitoring, and which is also used by System Center Operations Manager and Azure Stack Hub. A local attacker who already has low-privileged access to a machine running OMI can exploit the flaw to elevate privileges, gaining high-impact control over the confidentiality, integrity, and availability of the system (CVSS 3.1: 7.8, local attack vector, low privileges required, no user interaction). Any Azure tenant whose Linux VMs carry the silently installed OMI agent, as well as on-premises deployments that use OMI via System Center Operations Manager, is affected. The bug is one of four 'OMIGOD' flaws Microsoft patched in September 2021; CISA added it to the Known Exploited Vulnerabilities catalog on November 3, 2021, and researchers reported Mirai botnet activity exploiting OMI vulnerabilities, confirming in-the-wild exploitation even though no public proof-of-concept is known.

What to do: Apply Microsoft's patched OMI update across all affected products per vendor instructions, as required by the CISA KEV listing, and inventory Linux hosts and Azure management extensions for OMI (e.g., OMI/omsagent packages under /opt/omi) to confirm every agent has been updated. Because Azure services silently re-deploy OMI, re-check versions after updating and control which services auto-install it. Also limit exposure of OMI's HTTP listener to mitigate the related remote 'OMIGOD' RCE (CVE-2021-38647) on the same installs.

Affected
microsoft Open Management Infrastructure (OMI)
microsoft Azure Automation State ConfigurationDeployments bundling vulnerable OMI (unpatched)
microsoft Azure Automation Update ManagementDeployments bundling vulnerable OMI (unpatched)
microsoft Azure Diagnostics (LAD)Deployments bundling vulnerable OMI (unpatched)
microsoft Azure Security CenterDeployments bundling vulnerable OMI (unpatched)
microsoft Azure SentinelDeployments bundling vulnerable OMI (unpatched)
microsoft Azure Stack HubDeployments bundling vulnerable OMI (unpatched)
microsoft Container Monitoring SolutionDeployments bundling vulnerable OMI (unpatched)
microsoft Log Analytics AgentDeployments bundling vulnerable OMI (unpatched)
microsoft System Center Operations ManagerDeployments bundling vulnerable OMI (unpatched)
Estimated exposure
mass≈ millions of Azure Linux VMs and hybrid endpoints with the silently deployed OMI agent, affecting thousands of Azure customers — OMI is auto-installed by several widely used Azure management services on Linux VMs, and public research at disclosure ('OMIGOD') estimated millions of Azure endpoints had OMI deployed, with on-premises SCOM estates adding further…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Open Management Infrastructure Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Open Management Infrastructure (OMI)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
azure automation state configuration, azure automation update management, azure diagnostics \(lad\), azure security center, azure sentinel, azure stack hub, container monitoring solution, log analytics agent, open management infrastructure, system center operations manager
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news