First published: Wed Sep 15 2021(Updated: )
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
Credit: secure@microsoft.com secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure Automation State Configuration | ||
Microsoft Azure Automation Update Management | ||
Microsoft Azure Diagnostics \(lad\) | ||
Microsoft Azure Open Management Infrastructure | ||
Microsoft Azure Security Center | ||
Microsoft Azure Sentinel | ||
Microsoft Azure Stack Hub | ||
Microsoft Container Monitoring Solution | ||
Microsoft Log Analytics Agent | ||
Microsoft System Center Operations Manager | ||
Microsoft Open Management Infrastructure (OMI) | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38649 is a privilege escalation vulnerability in Microsoft Open Management Infrastructure (OMI).
CVE-2021-38649 has a severity rating of 7.8 (high).
Microsoft Open Management Infrastructure (OMI), Azure VM Management Extensions, Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics (LAD), Azure Security Center, Azure Sentinel, Azure Stack Hub, Container Monitoring Solution, Log Analytics Agent, and System Center Operations Manager are affected by CVE-2021-38649.
CVE-2021-38649 is an unspecified vulnerability in Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions that allows privilege escalation.
Yes, you can find more information about CVE-2021-38649 at [Microsoft Security Guidance Advisory](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38649).