ZeroHour

CVE-2021-38647

KEV ransomware PoC mass1

Unauthenticated RCE in Microsoft Open Management Infrastructure (OMI)

CISA: Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2021-38647 is an unauthenticated remote code execution flaw (CWE-1390, missing authentication) in Microsoft's Open Management Infrastructure (OMI), the open-source Linux management agent Microsoft bundles into Azure VM management extensions and System Center Operations Manager (SCOM) agents. When OMI is deployed through these extensions (for example the Log Analytics/OMS agent, Azure Monitor, or Azure Automation), its root-privileged server component listens for management traffic on the network (by default ports 5985/5986), and an attacker who can reach that port can send specially crafted, unauthenticated management requests that execute commands as root. Successful exploitation gives an attacker full root-level control of the affected Linux VM, turning network reachability into complete host compromise and a foothold for lateral movement. Any Azure Linux VM with an OMI-based management extension, plus standalone OMI or SCOM-agent deployments on Linux, is affected; CISA added the bug to the KEV on 2021-11-03 with known ransomware use, so exploitation is confirmed in the wild even though no public proof-of-concept is catalogued, and EPSS estimates a ~99.9% near-term exploitation probability.

What to do: Upgrade OMI to version 1.6.8-1 or later on all Linux VMs, including updating the bundled OMI inside Azure management extensions (Log Analytics/OMS agent, Azure Monitor, Azure Automation) and applying patched SCOM agent builds. Restrict network access to OMI's listener ports (5985/5986) with NSGs or host firewalls and check whether omiserver runs as root while binding beyond localhost. Because the flaw is in CISA KEV with known ransomware use, prioritize patching hosts whose OMI listener is reachable from untrusted networks and hunt for unexplained root-level activity.

Affected
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions
Estimated exposure
mass≈ millions of Linux VMs with OMI-based Azure management extensions — OMI is silently installed by very widely deployed Azure management extensions (Log Analytics/OMS agent, Azure Monitor, Azure Automation) and SCOM agents, and Microsoft publicly indicated the flaw affects millions of machines, though actual…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Open Management Infrastructure (OMI)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
azure automation state configuration, azure automation update management, azure diagnostics \(lad\), azure security center, azure sentinel, azure stack hub, container monitoring solution, log analytics agent, open management infrastructure, system center operations manager
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news