CVE-2021-38648
KEV PoC mass1Local Privilege Escalation in Microsoft Open Management Infrastructure (OMI)
CISA: Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
CVE-2021-38648 is an elevation-of-privilege vulnerability in Microsoft's Open Management Infrastructure (OMI), an open-source management agent that Microsoft silently installs on many Azure Linux virtual machines through commonly used Azure management extensions. A local attacker who already holds a low-privileged account on a host running a vulnerable OMI build can trigger the flaw to escalate privileges. Successful exploitation yields root-level control of the affected machine, and it can be chained with the related unauthenticated OMI remote code execution flaw (CVE-2021-38645) to go from remote access to full system compromise. Any system with OMI installed is affected, including Azure Linux VMs where OMI is bundled with Azure Security Center, Azure Sentinel, the Log Analytics agent, Azure Automation (Update Management and State Configuration), Azure Diagnostics (LAD), the Container Monitoring solution, Azure Stack Hub, and System Center Operations Manager. The flaw was added to CISA's KEV catalog on 2021-11-03, has a public security write-up reference, and is reported exploited in the wild (including by Mirai botnet operators per public reporting); EPSS assigns it an 11.4% probability of exploitation within 30 days (96th percentile).
What to do: Apply Microsoft's updated OMI packages per vendor instructions (the CISA KEV required action), prioritizing Linux VMs running Azure Security Center, Sentinel, Log Analytics, Azure Automation, Azure Diagnostics (LAD), Container Monitoring, Azure Stack Hub or System Center Operations Manager. Audit Linux hosts for the presence of the OMI agent (e.g., check installed packages and the OMI service) and remove or restrict it where it is not needed. When assessing remote exposure, also account for the related unauthenticated OMI RCE (CVE-2021-38645), which can be chained with this privilege escalation for full root compromise.
| microsoft Open Management Infrastructure (OMI) | — |
| microsoft Azure Open Management Infrastructure | — |
| microsoft Azure Automation State Configuration | — |
| microsoft Azure Automation Update Management | — |
| microsoft Azure Diagnostics (LAD) | — |
| microsoft Azure Security Center | — |
| microsoft Azure Sentinel | — |
| microsoft Azure Stack Hub | — |
| microsoft Container Monitoring Solution | — |
| microsoft Log Analytics Agent | — |
| microsoft System Center Operations Manager | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Open Management Infrastructure Elevation of Privilege Vulnerability
- Affected
- Microsoft Open Management Infrastructure (OMI)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- azure automation state configuration, azure automation update management, azure diagnostics \(lad\), azure open management infrastructure, azure security center, azure sentinel, azure stack hub, container monitoring solution, log analytics agent, open management infrastructure, system center operations manager
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H