CVE-2021-38645: Open Management Infrastructure Elevation of Privilege Vulnerability
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation.
Other sources
Open Management Infrastructure Elevation of Privilege Vulnerability
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-38645?
CVE-2021-38645 is a privilege escalation vulnerability found in Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions.
How severe is CVE-2021-38645?
CVE-2021-38645 has a severity rating of 7.8 out of 10, which is considered high.
Which software products are affected by CVE-2021-38645?
CVE-2021-38645 affects Microsoft Open Management Infrastructure (OMI), Microsoft Azure Automation State Configuration, Microsoft Azure Automation Update Management, Microsoft Open Management Infrastructure (OMI), Microsoft Azure Stack Hub, Microsoft Container Monitoring Solution, Microsoft Open Management Infrastructure (OMI), Microsoft Open Management Infrastructure (OMI), Microsoft Open Management Infrastructure (OMI), and Microsoft System Center Operations Manager.
How can I fix CVE-2021-38645?
To fix CVE-2021-38645, Microsoft has released a security update. It is recommended to apply the latest updates provided by Microsoft.
Where can I find more information about CVE-2021-38645?
You can find more information about CVE-2021-38645 on the Microsoft Security Guidance Advisory page at [https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38645](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38645).