ZeroHour

CVE-2021-38648

KEV PoC mass1

Local Privilege Escalation in Microsoft Open Management Infrastructure (OMI)

CISA: Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2021-38648 is an elevation-of-privilege vulnerability in Microsoft's Open Management Infrastructure (OMI), an open-source management agent that Microsoft silently installs on many Azure Linux virtual machines through commonly used Azure management extensions. A local attacker who already holds a low-privileged account on a host running a vulnerable OMI build can trigger the flaw to escalate privileges. Successful exploitation yields root-level control of the affected machine, and it can be chained with the related unauthenticated OMI remote code execution flaw (CVE-2021-38645) to go from remote access to full system compromise. Any system with OMI installed is affected, including Azure Linux VMs where OMI is bundled with Azure Security Center, Azure Sentinel, the Log Analytics agent, Azure Automation (Update Management and State Configuration), Azure Diagnostics (LAD), the Container Monitoring solution, Azure Stack Hub, and System Center Operations Manager. The flaw was added to CISA's KEV catalog on 2021-11-03, has a public security write-up reference, and is reported exploited in the wild (including by Mirai botnet operators per public reporting); EPSS assigns it an 11.4% probability of exploitation within 30 days (96th percentile).

What to do: Apply Microsoft's updated OMI packages per vendor instructions (the CISA KEV required action), prioritizing Linux VMs running Azure Security Center, Sentinel, Log Analytics, Azure Automation, Azure Diagnostics (LAD), Container Monitoring, Azure Stack Hub or System Center Operations Manager. Audit Linux hosts for the presence of the OMI agent (e.g., check installed packages and the OMI service) and remove or restrict it where it is not needed. When assessing remote exposure, also account for the related unauthenticated OMI RCE (CVE-2021-38645), which can be chained with this privilege escalation for full root compromise.

Affected
microsoft Open Management Infrastructure (OMI)
microsoft Azure Open Management Infrastructure
microsoft Azure Automation State Configuration
microsoft Azure Automation Update Management
microsoft Azure Diagnostics (LAD)
microsoft Azure Security Center
microsoft Azure Sentinel
microsoft Azure Stack Hub
microsoft Container Monitoring Solution
microsoft Log Analytics Agent
microsoft System Center Operations Manager
Estimated exposure
mass≈ millions of Azure Linux VMs with OMI silently bundled via management agents (tens of thousands externally exposed per public scans) — Public OMIGOD research and Azure deployment patterns indicate OMI is auto-installed on a large share of Azure Linux VMs through widely adopted extensions such as Security Center, Log Analytics and LAD, implying an install base in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Open Management Infrastructure Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Open Management Infrastructure (OMI)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
azure automation state configuration, azure automation update management, azure diagnostics \(lad\), azure open management infrastructure, azure security center, azure sentinel, azure stack hub, container monitoring solution, log analytics agent, open management infrastructure, system center operations manager
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news