EXPOSURES › CVE-2021-38649
CVE-2021-38649
HIGH ⌖ ON CISA KEV · EXPLOITEDA privilege escalation vulnerability in Microsoft's OMI within Azure VM Management Extensions was actively exploited in the wild.
Microsoft's Open Management Infrastructure (OMI) in Azure VM Management Extensions contained a privilege escalation vulnerability that was actively exploited in the wild. DIB organizations using Azure VMs must ensure this specific component is patched, as unpatched systems can lead to unauthorized access and potential data breaches. This highlights the critical need for continuous patch management, especially for cloud infrastructure components.
Shame score — The vulnerability was actively exploited in the wild, indicating a significant failure in patching and vulnerability management that could have been mitigated with timely updates.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
"Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation."
"CVEs and Security Vulnerabilities - OpenCVE"
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
"Browse 772 breaches across 20 industries."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |