First published: Wed Sep 15 2021(Updated: )
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure Automation State Configuration | ||
Microsoft Azure Automation Update Management | ||
Microsoft Azure Diagnostics \(lad\) | ||
Microsoft Azure Open Management Infrastructure | ||
Microsoft Azure Security Center | ||
Microsoft Azure Sentinel | ||
Microsoft Azure Stack Hub | ||
Microsoft Container Monitoring Solution | ||
Microsoft Log Analytics Agent | ||
Microsoft System Center Operations Manager | ||
Microsoft Open Management Infrastructure (OMI) | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38648 is a privilege escalation vulnerability in Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions.
CVE-2021-38648 has a severity rating of 7.8 (high).
CVE-2021-38648 affects Microsoft Open Management Infrastructure (OMI) and various other Microsoft products, including Azure Automation State Configuration, Azure Automation Update Management, and more.
The details of the exploitation of CVE-2021-38648 have not been specified.
More information about CVE-2021-38648 can be found at the following references: [http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html](http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html) and [https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648).