CVE-2021-38645
KEVmass1Local Privilege Escalation in Microsoft Open Management Infrastructure (OMI)
CISA: Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
CVE-2021-38645 is an elevation of privilege vulnerability in Microsoft's Open Management Infrastructure (OMI), a management agent that Microsoft silently deploys on Azure Linux virtual machines through services such as Azure Security Center, Azure Sentinel, Azure Automation (State Configuration and Update Management), Azure Diagnostics (LAD), the Log Analytics agent, and Container Monitoring, and which is also used by System Center Operations Manager and Azure Stack Hub. A local attacker who already has low-privileged access to a machine running OMI can exploit the flaw to elevate privileges, gaining high-impact control over the confidentiality, integrity, and availability of the system (CVSS 3.1: 7.8, local attack vector, low privileges required, no user interaction). Any Azure tenant whose Linux VMs carry the silently installed OMI agent, as well as on-premises deployments that use OMI via System Center Operations Manager, is affected. The bug is one of four 'OMIGOD' flaws Microsoft patched in September 2021; CISA added it to the Known Exploited Vulnerabilities catalog on November 3, 2021, and researchers reported Mirai botnet activity exploiting OMI vulnerabilities, confirming in-the-wild exploitation even though no public proof-of-concept is known.
What to do: Apply Microsoft's patched OMI update across all affected products per vendor instructions, as required by the CISA KEV listing, and inventory Linux hosts and Azure management extensions for OMI (e.g., OMI/omsagent packages under /opt/omi) to confirm every agent has been updated. Because Azure services silently re-deploy OMI, re-check versions after updating and control which services auto-install it. Also limit exposure of OMI's HTTP listener to mitigate the related remote 'OMIGOD' RCE (CVE-2021-38647) on the same installs.
| microsoft Open Management Infrastructure (OMI) | — |
| microsoft Azure Automation State Configuration | Deployments bundling vulnerable OMI (unpatched) |
| microsoft Azure Automation Update Management | Deployments bundling vulnerable OMI (unpatched) |
| microsoft Azure Diagnostics (LAD) | Deployments bundling vulnerable OMI (unpatched) |
| microsoft Azure Security Center | Deployments bundling vulnerable OMI (unpatched) |
| microsoft Azure Sentinel | Deployments bundling vulnerable OMI (unpatched) |
| microsoft Azure Stack Hub | Deployments bundling vulnerable OMI (unpatched) |
| microsoft Container Monitoring Solution | Deployments bundling vulnerable OMI (unpatched) |
| microsoft Log Analytics Agent | Deployments bundling vulnerable OMI (unpatched) |
| microsoft System Center Operations Manager | Deployments bundling vulnerable OMI (unpatched) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Open Management Infrastructure Elevation of Privilege Vulnerability
- Affected
- Microsoft Open Management Infrastructure (OMI)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- azure automation state configuration, azure automation update management, azure diagnostics \(lad\), azure security center, azure sentinel, azure stack hub, container monitoring solution, log analytics agent, open management infrastructure, system center operations manager
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H