EXPOSURES › CVE-2021-38648
CVE-2021-38648
HIGH ⌖ ON CISA KEV · EXPLOITEDA privilege escalation vulnerability in Microsoft's OMI within Azure VM Management Extensions was actively exploited in the wild.
Microsoft's Open Management Infrastructure (OMI) in Azure VM Management Extensions contained a privilege escalation vulnerability that was actively exploited in the wild. DIB organizations using Azure VMs must ensure this specific component is patched, as unpatched vulnerabilities in management extensions can lead to full system compromise and violate CMMC/NIST 800-171 requirements for patch management. The failure highlights the risk of relying on third-party management extensions without rigorous, continuous patching and monitoring.
Shame score — The vulnerability was actively exploited in the wild (KEV), indicating a significant lapse in patching and vulnerability management that allowed adversaries to escalate privileges on Azure VMs.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
"Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |