Vulnerability record · CVE-2021-38649 · published 15 September 2021
CVE-2021-38649: Microsoft Open Management Infrastructure local privilege escalation
Microsoft · Azure Automation State Configuration
CVE-2021-38649 is an elevation of privilege flaw in Microsoft's Open Management Infrastructure (OMI), the agent used by many Azure services and System Center Operations Manager. The record gives no root-cause detail beyond 'Insufficient information', so the exact defect is unknown, but a local low-privileged user can gain high confidentiality, integrity and availability impact on the host. It matters because OMI is widely deployed across Azure and on-premises management agents, and CISA added it to the Known Exploited Vulnerabilities catalog.
Description
Open Management Infrastructure Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a known-exploited local privilege escalation affecting widely deployed Microsoft management agents, though it requires an existing low-privileged foothold and the record lacks root-cause detail.
What it is
CVE-2021-38649 is an elevation of privilege flaw in Microsoft's Open Management Infrastructure (OMI), the agent used by many Azure services and System Center Operations Manager. The record gives no root-cause detail beyond 'Insufficient information', so the exact defect is unknown, but a local low-privileged user can gain high confidentiality, integrity and availability impact on the host. It matters because OMI is widely deployed across Azure and on-premises management agents, and CISA added it to the Known Exploited Vulnerabilities catalog.
Impact
An attacker who already has a foothold on the host can elevate from low privileges to full control of the affected system. That yields read and write access to data and services managed by the OMI agent.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker must already be able to run code on the target host. It is not remotely reachable over the network per the vector, and no authentication beyond the existing local session is needed.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2021-11-03 with a remediation due date of 2021-11-17, indicating exploitation in the wild. EPSS gives a 30-day probability of about 2.9 percent (86th percentile), and the record does not list ransomware use.
What to do
- Apply the Microsoft updates referenced in the MSRC advisory for CVE-2021-38649 as the first action.
- Inventory OMI deployments across Azure services, Log Analytics agents, Container Monitoring, Azure Sentinel, Azure Stack Hub and System Center Operations Manager, and patch each affected instance.
- Restrict local interactive and code-execution access on hosts running OMI to reduce the low-privileged foothold the flaw requires.
- Monitor the CISA KEV entry and vendor guidance for any updated remediation instructions.
Detection
- Hunt for unexpected privilege changes or new high-integrity processes spawned from OMI-related service processes on managed hosts.
- Alert on unusual local process execution or file writes in OMI installation and agent directories.
- Correlate host telemetry with OMI service restarts or configuration changes outside normal maintenance windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-38649 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38649 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38649 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38649 | US Government Resource |
Track CVE-2021-38649 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-38649), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.