Skip to content
COOEY

EXPOSURES › CVE-2021-38648

CVE-2021-38648

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-38648 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedprivilege-escalation

A privilege escalation vulnerability in Microsoft's OMI within Azure VM Management Extensions was actively exploited in the wild.

Microsoft's Open Management Infrastructure (OMI) in Azure VM Management Extensions contained a privilege escalation vulnerability that was actively exploited in the wild. DIB organizations using Azure VMs must ensure this specific component is patched, as unpatched vulnerabilities in management extensions can lead to full system compromise and violate CMMC/NIST 800-171 requirements for patch management. The failure highlights the risk of relying on third-party management extensions without rigorous, continuous patching and monitoring.

Shame score — The vulnerability was actively exploited in the wild (KEV), indicating a significant lapse in patching and vulnerability management that allowed adversaries to escalate privileges on Azure VMs.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Privilege escalation in Azure VM extensions is a critical security failure with severe fallout, though Microsoft's response was relatively standard and not heavily criticized in this specific source.
cooey ↗ severe-fallout -0.60
Critical vulnerability in Azure VM extensions, but source is NVD which is neutral in tone; however, the nature of the flaw (privilege escalation) inherently carries severe fallout.
"Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation."
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized