⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2021-11-17. Required action: Apply updates per vendor instructions..

CVE-2021-38649

Severity
7.8HIGH
EPSS
5.0%
top 10.27%
CISA KEV
KEV
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedSep 15
KEV addedNov 3
KEV dueNov 17
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Open Management Infrastructure Elevation of Privilege Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages9 packages

CVEListV5microsoft/open_management_infrastructure16.0OMI Version 1.6.8-1
CVEListV5microsoft/azure_automation_update_management1.0.0OMS Agent for Linux GA v1.13.40-0
CVEListV5microsoft/azure_sentinel1.0.0OMS Agent for Linux GA v1.13.40-0
CVEListV5microsoft/azure_stack_hub1.0.0Monitor, Update and Config Mgmnt 1.14.01+1
CVEListV5microsoft/log_analytics_agent1.0.0OMS Agent for Linux GA v1.13.40-0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9rvc-mxjm-qh6v: Open Management Infrastructure Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-38645, CVE-2021-386482022-05-24
CVEList
Open Management Infrastructure Elevation of Privilege Vulnerability2021-09-15
VulnCheck
Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability2021

📋Vendor Advisories

2
CISA
Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability2021-11-03
Microsoft
Open Management Infrastructure Elevation of Privilege Vulnerability2021-09-14

🕵️Threat Intelligence

1
Unit42
Threat Brief: OMI Vulnerabilities (CVE-2021-38645, CVE-2021-38647, CVE-2021-38648 and CVE-2021-38649)2021-09-16
CVE-2021-38649 (HIGH CVSS 7.8) | Open Management Infrastructure Elev | cvebase.io