CVE-2021-38648
Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability
Description
CVE-2021-38648 is a high-severity privilege escalation vulnerability in Microsoft Open Management Infrastructure (OMI), a management agent deployed within Azure VM Management Extensions. The vulnerability allows a local attacker with low-level privileges to escalate to higher system privileges on affected Azure virtual machines and Linux hosts running OMI. CISA has added CVE-2021-38648 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS score of 31.79% (96.7th percentile), this OMI privilege escalation vulnerability poses a very high exploitation risk, particularly for organizations relying on Azure cloud services.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | azure automation state configuration | - |
| microsoft | azure automation update management | - |
| microsoft | azure diagnostics \(lad\) | - |
| microsoft | azure open management infrastructure | - |
| microsoft | azure security center | - |
| microsoft | azure sentinel | - |
| microsoft | azure stack hub | - |
| microsoft | container monitoring solution | - |
| microsoft | log analytics agent | - |
| microsoft | open management infrastructure | < 1.6.8-1 |
| microsoft | system center operations manager | - |
Multiple CVSS Assessments
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38648(Patch, Vendor Advisory)
- http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html(Exploit, Third Party Advisory, VDB Entry)
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38648(US Government Resource)
Weakness Type
Privilege Escalation in Open Management Infrastructure
The Open Management Infrastructure (OMI) agent contains an unspecified vulnerability that enables elevation of privilege. OMI is a lightweight management agent used across multiple Azure services, and its privilege escalation flaw allows a locally authenticated attacker to gain higher system privileges, potentially achieving root-level access on the Linux hosts where OMI is installed.
Learn more: CVE-2021-38648 — NVD Detail
Impact Analysis
CVE-2021-38648 carries a CVSS 3.1 score of 7.8 (HIGH), indicating a serious security threat to Azure cloud environments. The vulnerability is locally exploitable with low attack complexity, requires only low-level privileges, and needs no user interaction, making it readily accessible to any authenticated user on an affected system. Successful exploitation results in maximum impact on confidentiality, integrity, and availability, as the attacker gains elevated privileges potentially up to root access. The broad deployment surface of OMI across numerous Azure services — including Azure Automation, Azure Security Center, Azure Sentinel, Azure Diagnostics, Log Analytics Agent, and System Center Operations Manager — significantly amplifies the risk. The EPSS score of 31.79% (96.7th percentile) indicates a very high probability of exploitation, placing CVE-2021-38648 in the top 4% of all CVEs by exploitation likelihood.
Exploit Maturity
CVE-2021-38648 has a well-established exploit presence. Public exploit code is available via Packet Storm Security, demonstrating exploitation of the OMI management interface. CISA has confirmed active exploitation in the wild by including CVE-2021-38648 in the Known Exploited Vulnerabilities catalog, with a remediation deadline of 2021-11-17. The EPSS score of 31.79% (96.7th percentile) indicates a very high probability of exploitation, placing this vulnerability among the most actively targeted in the wild. This vulnerability is part of a broader set of OMI vulnerabilities disclosed in September 2021, collectively known as "OMIGOD," which attracted significant attacker attention due to the widespread deployment of OMI across Azure infrastructure.
Remediation
- Apply Microsoft security updates immediately as required by CISA KEV guidance. Microsoft released patches for the OMI privilege escalation vulnerability as part of the September 2021 security updates.
- Verify that all Azure services utilizing OMI have been updated, including: Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Open Management Infrastructure, Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, and System Center Operations Manager.
- For Azure VMs, check the OMI version installed and ensure it is updated to the patched release. Run
/opt/omi/bin/omiserver --versionon Linux VMs to verify the current version. Update OMI packages via the distribution's package manager or through Azure VM extension updates. - Implement network segmentation to restrict access to OMI management ports (typically port 5986 for HTTPS and 5985 for HTTP). Monitor for unauthorized connections to these ports and unusual privilege escalation activity on Linux hosts.
- Conduct a security audit of all Azure subscriptions to inventory OMI deployments and confirm that patches have been applied consistently across all virtual machines and managed services.
Technical Details
CVE-2021-38648 affects the Open Management Infrastructure (OMI) agent, a lightweight WS-Management protocol implementation used by Microsoft for Linux-based management in Azure environments. OMI runs as a privileged service on Linux hosts and is automatically deployed through various Azure VM management extensions. The vulnerability allows a locally authenticated attacker with low privileges to escalate to higher system privileges through exploitation of the OMI agent's internal operations. The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms that exploitation requires local access with low privileges, involves minimal complexity, and requires no user interaction. The scope remains unchanged, but since OMI operates with elevated privileges on the host system, successful exploitation effectively grants root-level access with full control over the affected Linux virtual machine.
Frequently Asked Questions
Is CVE-2021-38648 being actively exploited?
Yes. CVE-2021-38648 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Public exploit code is available and the EPSS score of 31.79% (96.7th percentile) indicates a very high probability of exploitation. This vulnerability is part of the "OMIGOD" vulnerability set that attracted widespread attacker attention.
What products are affected by CVE-2021-38648?
CVE-2021-38648 affects Microsoft Open Management Infrastructure (OMI) as deployed across multiple Azure services, including Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, and System Center Operations Manager.
How do I fix CVE-2021-38648?
Apply the September 2021 Microsoft security updates immediately. Check the OMI version on all affected Linux VMs using /opt/omi/bin/omiserver --version and update to the patched release. Restrict network access to OMI management ports and audit all Azure subscriptions for unpatched OMI deployments.
How severe is CVE-2021-38648?
CVE-2021-38648 has a CVSS 3.1 score of 7.8 (HIGH). Its broad deployment across Azure services, confirmed active exploitation, and very high EPSS score of 31.79% (96.7th percentile) make it a critical remediation priority for any organization using Azure infrastructure.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.