CVE-2021-38648: Open Management Infrastructure Elevation of Privilege Vulnerability
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
Other sources
Open Management Infrastructure Elevation of Privilege Vulnerability
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-38648?
CVE-2021-38648 is a privilege escalation vulnerability in Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions.
What is the severity rating of CVE-2021-38648?
CVE-2021-38648 has a severity rating of 7.8 (high).
Which software products are affected by CVE-2021-38648?
CVE-2021-38648 affects Microsoft Open Management Infrastructure (OMI) and various other Microsoft products, including Azure Automation State Configuration, Azure Automation Update Management, and more.
How can the privilege escalation vulnerability in CVE-2021-38648 be exploited?
The details of the exploitation of CVE-2021-38648 have not been specified.
Where can I find more information about CVE-2021-38648?
More information about CVE-2021-38648 can be found at the following references: [http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html](http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html) and [https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648).