Sep 2021: Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38648 Published on September 15, 2021

Open Management Infrastructure Elevation of Privilege Vulnerability
Open Management Infrastructure Elevation of Privilege Vulnerability

NVD

Known Exploited Vulnerability

This Microsoft Azure Open Management Infrastructure (OMI) Privilege Escalation Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Open Management Infrastructure Privilege Escalation Vulnerability.

The following remediation steps are recommended / required by November 17, 2021: Apply updates per vendor instructions.


Products Associated with CVE-2021-38648

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

Microsoft Open Management Infrastructure: Microsoft System Center Operations Manager (SCOM): Microsoft Azure Automation State Configuration, DSC Extension: Microsoft Azure Automation Update Management: Microsoft Log Analytics Agent: Microsoft Azure Diagnostics (LAD): Microsoft Container Monitoring Solution: Microsoft Azure Security Center: Microsoft Azure Sentinel: Microsoft Azure Stack Hub:

Exploit Probability

EPSS
31.79%
Percentile
96.74%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.