ZeroHour

CVE-2021-38649

KEVlarge

Local Privilege Escalation in Microsoft Open Management Infrastructure (OMI)

CISA: Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

CVSS 3.1
7.0 high
EPSS
3%p86
Published
()
KEV added
AI analysis

Open Management Infrastructure (OMI) is an open-source management agent that Microsoft silently installs on many Azure Linux VMs via management extensions (Security Center, Sentinel, Azure Monitor/Log Analytics, Automation, Azure Diagnostics) and also ships with System Center Operations Manager; CVE-2021-38649 is an elevation-of-privilege vulnerability in it. A low-privileged local account or process on a host running OMI can trigger the flaw — under conditions classified as high attack complexity and with no user interaction required — to elevate its privileges. An attacker who already has a foothold gains high-impact elevated privileges (high confidentiality, integrity and availability impact), enabling persistence, tampering and lateral movement on the affected VM or server. Any organization running OMI through the listed Azure services, the Log Analytics agent, Azure Stack Hub, or SCOM is affected, especially Azure Linux VMs where OMI was deployed without administrators' explicit knowledge. Exploitation is confirmed in the wild: CISA added the CVE to KEV on 2021-11-03 with a required action to apply vendor updates, EPSS estimates a 2.9% (86th-percentile) probability of exploitation within 30 days, and the related OMIGOD flaws have drawn Mirai botnet activity; fixes shipped in Microsoft's September 2021 updates.

What to do: Apply Microsoft's OMI updates per vendor instructions (the OMIGOD fixes released in September 2021) and update the affected Azure extensions, the Log Analytics agent, and SCOM components on all Linux VMs and servers. Audit Linux VMs and managed servers for silently installed OMI and remove it where it is not needed; while patching is pending, restrict untrusted low-privileged local access on OMI hosts. Confirm remediation against the CISA KEV required action (apply updates per vendor instructions).

Affected
Microsoft Open Management Infrastructure (OMI)
Microsoft Azure Open Management Infrastructure
Microsoft Azure Automation State Configuration
Microsoft Azure Automation Update Management
Microsoft Azure Diagnostics (LAD)
Microsoft Azure Security Center
Microsoft Azure Sentinel
Microsoft Azure Stack Hub
Microsoft Container Monitoring Solution
Microsoft Log Analytics Agent
Microsoft System Center Operations Manager
Estimated exposure
large≈100,000+ systems (hundreds of thousands of Azure-managed Linux VMs and agent-monitored endpoints with silently installed OMI) — Estimated from OMIGOD coverage reporting that Microsoft secretly installs OMI through Azure management extensions on a large share of Azure Linux VMs, with headlines citing thousands of affected Azure customers whose VM fleets collectively…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Open Management Infrastructure Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Open Management Infrastructure (OMI)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
azure automation state configuration, azure automation update management, azure diagnostics \(lad\), azure open management infrastructure, azure security center, azure sentinel, azure stack hub, container monitoring solution, log analytics agent, open management infrastructure, system center operations manager
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news