CVE-2021-38649
KEVlargeLocal Privilege Escalation in Microsoft Open Management Infrastructure (OMI)
CISA: Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
Open Management Infrastructure (OMI) is an open-source management agent that Microsoft silently installs on many Azure Linux VMs via management extensions (Security Center, Sentinel, Azure Monitor/Log Analytics, Automation, Azure Diagnostics) and also ships with System Center Operations Manager; CVE-2021-38649 is an elevation-of-privilege vulnerability in it. A low-privileged local account or process on a host running OMI can trigger the flaw — under conditions classified as high attack complexity and with no user interaction required — to elevate its privileges. An attacker who already has a foothold gains high-impact elevated privileges (high confidentiality, integrity and availability impact), enabling persistence, tampering and lateral movement on the affected VM or server. Any organization running OMI through the listed Azure services, the Log Analytics agent, Azure Stack Hub, or SCOM is affected, especially Azure Linux VMs where OMI was deployed without administrators' explicit knowledge. Exploitation is confirmed in the wild: CISA added the CVE to KEV on 2021-11-03 with a required action to apply vendor updates, EPSS estimates a 2.9% (86th-percentile) probability of exploitation within 30 days, and the related OMIGOD flaws have drawn Mirai botnet activity; fixes shipped in Microsoft's September 2021 updates.
What to do: Apply Microsoft's OMI updates per vendor instructions (the OMIGOD fixes released in September 2021) and update the affected Azure extensions, the Log Analytics agent, and SCOM components on all Linux VMs and servers. Audit Linux VMs and managed servers for silently installed OMI and remove it where it is not needed; while patching is pending, restrict untrusted low-privileged local access on OMI hosts. Confirm remediation against the CISA KEV required action (apply updates per vendor instructions).
| Microsoft Open Management Infrastructure (OMI) | — |
| Microsoft Azure Open Management Infrastructure | — |
| Microsoft Azure Automation State Configuration | — |
| Microsoft Azure Automation Update Management | — |
| Microsoft Azure Diagnostics (LAD) | — |
| Microsoft Azure Security Center | — |
| Microsoft Azure Sentinel | — |
| Microsoft Azure Stack Hub | — |
| Microsoft Container Monitoring Solution | — |
| Microsoft Log Analytics Agent | — |
| Microsoft System Center Operations Manager | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Open Management Infrastructure Elevation of Privilege Vulnerability
- Affected
- Microsoft Open Management Infrastructure (OMI)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- azure automation state configuration, azure automation update management, azure diagnostics \(lad\), azure open management infrastructure, azure security center, azure sentinel, azure stack hub, container monitoring solution, log analytics agent, open management infrastructure, system center operations manager
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H