Vulnerability record · CVE-2021-38647 · published 15 September 2021
CVE-2021-38647: Microsoft OMI Authentication Bypass Enables Remote Code Execution
Microsoft · Azure Automation State Configuration
CVE-2021-38647 is a critical remote code execution flaw in Microsoft's Open Management Infrastructure (OMI), the agent used by many Azure and System Center services. The vulnerability allows an unauthenticated attacker to bypass authentication and execute code with high impact to confidentiality, integrity, and availability. It is known to be exploited in the wild and has been used in ransomware campaigns.
Description
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe vulnerability is remotely exploitable without authentication, has a CVSS score of 9.8, is actively exploited in ransomware campaigns, and has a near-maximum EPSS score.
What it is
CVE-2021-38647 is a critical remote code execution flaw in Microsoft's Open Management Infrastructure (OMI), the agent used by many Azure and System Center services. The vulnerability allows an unauthenticated attacker to bypass authentication and execute code with high impact to confidentiality, integrity, and availability. It is known to be exploited in the wild and has been used in ransomware campaigns.
Impact
An unauthenticated remote attacker can execute arbitrary code on affected systems, potentially leading to full system compromise. This can result in data theft, service disruption, and deployment of ransomware.
Attack surface
The flaw is reachable over the network via the OMI management interface, requiring no authentication or user interaction. The CVSS vector confirms network access with low complexity and no privileges needed.
Exploitation
CVE-2021-38647 is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, and public exploit code is available. EPSS probability is 0.99933, indicating near-certain exploitation in the next 30 days.
What to do
- Apply the vendor patches referenced in Microsoft's security advisory immediately.
- If patching is not possible, restrict network access to OMI ports (typically 5985/5986) to trusted hosts only.
- Monitor for signs of compromise and isolate affected systems until patched.
- Follow CISA's required action to apply updates per vendor instructions by the due date.
Detection
- Monitor for unusual network traffic to OMI ports (5985/5986) from untrusted sources.
- Look for unexpected process creation or command execution on systems running OMI, especially from the OMI service account.
- Review logs for authentication bypass attempts or anomalous OMI management activity.
- Use endpoint detection to flag known exploit patterns or tools targeting OMI.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-38647 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/164694/Microsoft-OMI-Management-Interface-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38647 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38647 | US Government Resource |
Track CVE-2021-38647 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-38647), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.