LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-38648: Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-38648 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

CVE-2021-38648 is a privilege escalation vulnerability in Microsoft Open Management Infrastructure (OMI), a component used within Azure VM Management Extensions. An attacker who can reach the affected service may be able to gain higher privileges on the host. Because OMI often runs with elevated rights in cloud and hybrid management scenarios, successful abuse can expand an initial foothold into broader control of the virtual machine or management plane. Confirm all product and version details against the vendor advisory.

How it works

The weakness is categorized as CWE-1390. In general terms for this class, the software fails to enforce proper authorization or authentication boundaries when handling requests, allowing a lower-privileged principal to perform actions or obtain access reserved for higher privileges. CISA describes the issue as an unspecified vulnerability in OMI within Azure VM Management Extensions that permits privilege escalation. Public detail on exact request formats or internal checks is limited; defenders should treat any reachable OMI endpoint as potentially abusable until patched and should not rely on unconfirmed exploit narratives. An attacker who already has some level of access—local or via a compromised management path—could leverage the flaw to elevate privileges on the system running OMI.

Am I affected? How to find it in your systems

OMI commonly appears on Linux virtual machines in Azure that use management extensions, as well as in other environments where Microsoft management agents are installed. Inventory steps include:

Telemetry signs of exploitation are not detailed in the provided facts. In general for privilege-escalation issues of this type, watch for unexpected process elevation, unusual service account activity, or anomalous local authentication events around the OMI service. Correlate with Azure activity logs and host-based detection for post-exploitation behavior.

How to remediate

Apply the updates Microsoft released for this vulnerability, following the vendor instructions referenced by CISA. Prioritize systems that expose OMI or run Azure VM Management Extensions. After patching:

Where possible, remove OMI or unused management extensions from systems that do not require them.

If you can't patch immediately

Reduce exposure until the vendor update can be applied:

These measures lower risk but do not replace the official update.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities can lead to full host compromise and subsequent data access or lateral movement. Known ransomware use is not documented for this CVE. If you suspect compromise, isolate affected systems, preserve logs, and follow your incident-response process. You can run a free exposure scan of your email addresses against known breach data to check whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Open Management Infrastructure (OMI)
WeaknessCWE-1390
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities