CVE-2021-38648

HIGH(7.8)KEVElevated Risk

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

Description

CVE-2021-38648 is a high-severity privilege escalation vulnerability in Microsoft Open Management Infrastructure (OMI), a management agent deployed within Azure VM Management Extensions. The vulnerability allows a local attacker with low-level privileges to escalate to higher system privileges on affected Azure virtual machines and Linux hosts running OMI. CISA has added CVE-2021-38648 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS score of 31.79% (96.7th percentile), this OMI privilege escalation vulnerability poses a very high exploitation risk, particularly for organizations relying on Azure cloud services.

KEV Information

Vendor
Microsoft
Product
Open Management Infrastructure (OMI)
Date Added
November 3, 2021
Due Date
November 17, 2021
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

Affected Products

VendorProductVersion
microsoftazure automation state configuration-
microsoftazure automation update management-
microsoftazure diagnostics \(lad\)-
microsoftazure open management infrastructure-
microsoftazure security center-
microsoftazure sentinel-
microsoftazure stack hub-
microsoftcontainer monitoring solution-
microsoftlog analytics agent-
microsoftopen management infrastructure< 1.6.8-1
microsoftsystem center operations manager-

Multiple CVSS Assessments

Source: [email protected](Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: [email protected](Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

Privilege Escalation in Open Management Infrastructure

The Open Management Infrastructure (OMI) agent contains an unspecified vulnerability that enables elevation of privilege. OMI is a lightweight management agent used across multiple Azure services, and its privilege escalation flaw allows a locally authenticated attacker to gain higher system privileges, potentially achieving root-level access on the Linux hosts where OMI is installed.

Learn more: CVE-2021-38648 — NVD Detail

Impact Analysis

CVE-2021-38648 carries a CVSS 3.1 score of 7.8 (HIGH), indicating a serious security threat to Azure cloud environments. The vulnerability is locally exploitable with low attack complexity, requires only low-level privileges, and needs no user interaction, making it readily accessible to any authenticated user on an affected system. Successful exploitation results in maximum impact on confidentiality, integrity, and availability, as the attacker gains elevated privileges potentially up to root access. The broad deployment surface of OMI across numerous Azure services — including Azure Automation, Azure Security Center, Azure Sentinel, Azure Diagnostics, Log Analytics Agent, and System Center Operations Manager — significantly amplifies the risk. The EPSS score of 31.79% (96.7th percentile) indicates a very high probability of exploitation, placing CVE-2021-38648 in the top 4% of all CVEs by exploitation likelihood.

Exploit Maturity

CVE-2021-38648 has a well-established exploit presence. Public exploit code is available via Packet Storm Security, demonstrating exploitation of the OMI management interface. CISA has confirmed active exploitation in the wild by including CVE-2021-38648 in the Known Exploited Vulnerabilities catalog, with a remediation deadline of 2021-11-17. The EPSS score of 31.79% (96.7th percentile) indicates a very high probability of exploitation, placing this vulnerability among the most actively targeted in the wild. This vulnerability is part of a broader set of OMI vulnerabilities disclosed in September 2021, collectively known as "OMIGOD," which attracted significant attacker attention due to the widespread deployment of OMI across Azure infrastructure.

Remediation

  1. Apply Microsoft security updates immediately as required by CISA KEV guidance. Microsoft released patches for the OMI privilege escalation vulnerability as part of the September 2021 security updates.
  2. Verify that all Azure services utilizing OMI have been updated, including: Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Open Management Infrastructure, Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, and System Center Operations Manager.
  3. For Azure VMs, check the OMI version installed and ensure it is updated to the patched release. Run /opt/omi/bin/omiserver --version on Linux VMs to verify the current version. Update OMI packages via the distribution's package manager or through Azure VM extension updates.
  4. Implement network segmentation to restrict access to OMI management ports (typically port 5986 for HTTPS and 5985 for HTTP). Monitor for unauthorized connections to these ports and unusual privilege escalation activity on Linux hosts.
  5. Conduct a security audit of all Azure subscriptions to inventory OMI deployments and confirm that patches have been applied consistently across all virtual machines and managed services.

Technical Details

CVE-2021-38648 affects the Open Management Infrastructure (OMI) agent, a lightweight WS-Management protocol implementation used by Microsoft for Linux-based management in Azure environments. OMI runs as a privileged service on Linux hosts and is automatically deployed through various Azure VM management extensions. The vulnerability allows a locally authenticated attacker with low privileges to escalate to higher system privileges through exploitation of the OMI agent's internal operations. The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms that exploitation requires local access with low privileges, involves minimal complexity, and requires no user interaction. The scope remains unchanged, but since OMI operates with elevated privileges on the host system, successful exploitation effectively grants root-level access with full control over the affected Linux virtual machine.

Frequently Asked Questions

Is CVE-2021-38648 being actively exploited?

Yes. CVE-2021-38648 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Public exploit code is available and the EPSS score of 31.79% (96.7th percentile) indicates a very high probability of exploitation. This vulnerability is part of the "OMIGOD" vulnerability set that attracted widespread attacker attention.

What products are affected by CVE-2021-38648?

CVE-2021-38648 affects Microsoft Open Management Infrastructure (OMI) as deployed across multiple Azure services, including Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, and System Center Operations Manager.

How do I fix CVE-2021-38648?

Apply the September 2021 Microsoft security updates immediately. Check the OMI version on all affected Linux VMs using /opt/omi/bin/omiserver --version and update to the patched release. Restrict network access to OMI management ports and audit all Azure subscriptions for unpatched OMI deployments.

How severe is CVE-2021-38648?

CVE-2021-38648 has a CVSS 3.1 score of 7.8 (HIGH). Its broad deployment across Azure services, confirmed active exploitation, and very high EPSS score of 31.79% (96.7th percentile) make it a critical remediation priority for any organization using Azure infrastructure.

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score11.42%
EPSS Percentile95.7%

Dates

PublishedSeptember 15, 2021
Last ModifiedAugust 10, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.