EXPOSURES › CVE-2021-38647
CVE-2021-38647
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA Microsoft OMI vulnerability allowed remote code execution, actively exploited in ransomware attacks, impacting Azure VM Management Extensions.
The unspecified vulnerability in Microsoft's OMI allowed attackers to execute code remotely, potentially compromising Azure VMs and leading to data breaches or ransomware infections. DIB organizations using Azure VMs should immediately patch affected systems and review VM management extension configurations to prevent exploitation. Failure to address this vulnerability can lead to significant compliance failures under CMMC and NIST 800-171.
Shame score — The vulnerability's exploitation in ransomware attacks and its presence within a critical Azure component demonstrates a significant security oversight with potentially widespread impact.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
"Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |