Skip to content
COOEY

EXPOSURES › CVE-2021-38649

CVE-2021-38649

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-38649 ↗
⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatchedprivilege-escalation

A privilege escalation vulnerability in Microsoft's OMI within Azure VM Management Extensions was actively exploited in the wild.

Microsoft's Open Management Infrastructure (OMI) in Azure VM Management Extensions contained a privilege escalation vulnerability that was actively exploited in the wild. DIB organizations using Azure VMs must ensure this specific component is patched, as unpatched systems can lead to unauthorized access and potential data breaches. This highlights the critical need for continuous patch management, especially for cloud infrastructure components.

Shame score — The vulnerability was actively exploited in the wild, indicating a significant failure in patching and vulnerability management that could have been mitigated with timely updates.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Significant negative reception due to unspecified vulnerability and potential privilege escalation.
cooey ↗ severe-fallout -0.80
Neutral reporting of the vulnerability.
"Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation."
app.opencve.io ↗ severe-fallout +0.00
Generic listing, no sentiment.
"CVEs and Security Vulnerabilities - OpenCVE"
app.opencve.io ↗ severe-fallout +0.00
Generic listing, no sentiment.
"CVEs to check"
www.cvefind.com ↗ severe-fallout +0.00
Generic listing, no sentiment.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
xposedornot.com ↗ severe-fallout +0.00
Generic listing, no sentiment.
"Browse 772 breaches across 20 industries."
CISA ↗ severe-fallout +0.00
Generic listing, no sentiment.
"ICS Advisories | CISA"
www.microsoft.com ↗ severe-fallout +0.00
Generic listing, no sentiment.
"Microsoft Security Blog"
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized