← Vulnerability feed

Vulnerability record · CVE-2021-38648 · published 15 September 2021

CVE-2021-38648: Microsoft Open Management Infrastructure local privilege escalation

Microsoft · Azure Automation State Configuration

CVE-2021-38648 is an elevation of privilege flaw in Microsoft's Open Management Infrastructure (OMI), the management stack embedded in many Azure services and agents. A local attacker with low privileges can exploit it to gain higher privileges on the host, which matters because OMI ships broadly across Azure and System Center products. The record gives no root-cause detail beyond 'insufficient information' for the CWE.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 11% · top 4.1%
7.8CVSS 3.1 base score, v2 4.6
11%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
11Affected product versions listed by NVD
4References, 1 tagged exploit
10 Aug 2026Last modified by NVD

Description

Open Management Infrastructure Elevation of Privilege Vulnerability

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is confirmed exploited in the wild and listed in CISA KEV, but it requires local access and low privileges, which limits broad remote exploitation.

What it is

CVE-2021-38648 is an elevation of privilege flaw in Microsoft's Open Management Infrastructure (OMI), the management stack embedded in many Azure services and agents. A local attacker with low privileges can exploit it to gain higher privileges on the host, which matters because OMI ships broadly across Azure and System Center products. The record gives no root-cause detail beyond 'insufficient information' for the CWE.

Impact

An attacker who already has a foothold on a host can elevate to higher privileges, potentially to root or SYSTEM, gaining full control of the affected system. That control can be used to move laterally or disable defenses.

Attack surface

The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the flaw is reached by an attacker already executing code on the target host, not remotely over the network. No authentication beyond the existing local session is needed.

Exploitation

CVE-2021-38648 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and a public exploit reference exists on Packet Storm, so exploitation is confirmed in the wild. EPSS gives a 30-day probability of about 11.4 percent (95.8th percentile), indicating elevated activity.

What to do

  • Apply the Microsoft updates referenced in the MSRC advisory for CVE-2021-38648 as the first action.
  • Inventory all hosts and Azure services running OMI, including Log Analytics agent, Azure Automation, Azure Sentinel, Security Center, and System Center Operations Manager, and confirm patch status.
  • Restrict local interactive and service account access on OMI-bearing hosts to reduce the pool of low-privileged users who can trigger the flaw.
  • Where OMI is not required, remove or disable the agent to shrink the attack surface.
  • Monitor CISA KEV guidance and apply the vendor-required action by the stated due date.

Detection

  • Alert on unexpected privilege changes or new high-privilege processes spawned from OMI-related service processes.
  • Monitor for local exploitation attempts against OMI management interfaces, including unusual authentication or process behavior on OMI ports.
  • Audit hosts for unpatched OMI versions and correlate with any local user activity preceding privilege escalation.
  • Review logs for post-exploitation behavior such as new admin accounts, credential access, or defense evasion on OMI-bearing systems.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-38648 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-38648 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2021-38648), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.