← Vulnerability feed

Vulnerability record · CVE-2021-38647 · published 15 September 2021

CVE-2021-38647: Microsoft OMI Authentication Bypass Enables Remote Code Execution

Microsoft · Azure Automation State Configuration

CVE-2021-38647 is a critical remote code execution flaw in Microsoft's Open Management Infrastructure (OMI), the agent used by many Azure and System Center services. The vulnerability allows an unauthenticated attacker to bypass authentication and execute code with high impact to confidentiality, integrity, and availability. It is known to be exploited in the wild and has been used in ransomware campaigns.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1%
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
10Affected product versions listed by NVD
4References, 1 tagged exploit
10 Aug 2026Last modified by NVD

Description

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe vulnerability is remotely exploitable without authentication, has a CVSS score of 9.8, is actively exploited in ransomware campaigns, and has a near-maximum EPSS score.

What it is

CVE-2021-38647 is a critical remote code execution flaw in Microsoft's Open Management Infrastructure (OMI), the agent used by many Azure and System Center services. The vulnerability allows an unauthenticated attacker to bypass authentication and execute code with high impact to confidentiality, integrity, and availability. It is known to be exploited in the wild and has been used in ransomware campaigns.

Impact

An unauthenticated remote attacker can execute arbitrary code on affected systems, potentially leading to full system compromise. This can result in data theft, service disruption, and deployment of ransomware.

Attack surface

The flaw is reachable over the network via the OMI management interface, requiring no authentication or user interaction. The CVSS vector confirms network access with low complexity and no privileges needed.

Exploitation

CVE-2021-38647 is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, and public exploit code is available. EPSS probability is 0.99933, indicating near-certain exploitation in the next 30 days.

What to do

  • Apply the vendor patches referenced in Microsoft's security advisory immediately.
  • If patching is not possible, restrict network access to OMI ports (typically 5985/5986) to trusted hosts only.
  • Monitor for signs of compromise and isolate affected systems until patched.
  • Follow CISA's required action to apply updates per vendor instructions by the due date.

Detection

  • Monitor for unusual network traffic to OMI ports (5985/5986) from untrusted sources.
  • Look for unexpected process creation or command execution on systems running OMI, especially from the OMI service account.
  • Review logs for authentication bypass attempts or anomalous OMI management activity.
  • Use endpoint detection to flag known exploit patterns or tools targeting OMI.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-38647 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-38647 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2021-38647), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.