Vulnerability record · CVE-2021-38648 · published 15 September 2021
CVE-2021-38648: Microsoft Open Management Infrastructure local privilege escalation
Microsoft · Azure Automation State Configuration
CVE-2021-38648 is an elevation of privilege flaw in Microsoft's Open Management Infrastructure (OMI), the management stack embedded in many Azure services and agents. A local attacker with low privileges can exploit it to gain higher privileges on the host, which matters because OMI ships broadly across Azure and System Center products. The record gives no root-cause detail beyond 'insufficient information' for the CWE.
Description
Open Management Infrastructure Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is confirmed exploited in the wild and listed in CISA KEV, but it requires local access and low privileges, which limits broad remote exploitation.
What it is
CVE-2021-38648 is an elevation of privilege flaw in Microsoft's Open Management Infrastructure (OMI), the management stack embedded in many Azure services and agents. A local attacker with low privileges can exploit it to gain higher privileges on the host, which matters because OMI ships broadly across Azure and System Center products. The record gives no root-cause detail beyond 'insufficient information' for the CWE.
Impact
An attacker who already has a foothold on a host can elevate to higher privileges, potentially to root or SYSTEM, gaining full control of the affected system. That control can be used to move laterally or disable defenses.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the flaw is reached by an attacker already executing code on the target host, not remotely over the network. No authentication beyond the existing local session is needed.
Exploitation
CVE-2021-38648 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and a public exploit reference exists on Packet Storm, so exploitation is confirmed in the wild. EPSS gives a 30-day probability of about 11.4 percent (95.8th percentile), indicating elevated activity.
What to do
- Apply the Microsoft updates referenced in the MSRC advisory for CVE-2021-38648 as the first action.
- Inventory all hosts and Azure services running OMI, including Log Analytics agent, Azure Automation, Azure Sentinel, Security Center, and System Center Operations Manager, and confirm patch status.
- Restrict local interactive and service account access on OMI-bearing hosts to reduce the pool of low-privileged users who can trigger the flaw.
- Where OMI is not required, remove or disable the agent to shrink the attack surface.
- Monitor CISA KEV guidance and apply the vendor-required action by the stated due date.
Detection
- Alert on unexpected privilege changes or new high-privilege processes spawned from OMI-related service processes.
- Monitor for local exploitation attempts against OMI management interfaces, including unusual authentication or process behavior on OMI ports.
- Audit hosts for unpatched OMI versions and correlate with any local user activity preceding privilege escalation.
- Review logs for post-exploitation behavior such as new admin accounts, credential access, or defense evasion on OMI-bearing systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-38648 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38648 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38648 | US Government Resource |
Track CVE-2021-38648 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-38648), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.