CISA Known Exploited Vulnerability

CVE-2021-38648

Microsoft · Open Management Infrastructure (OMI)

Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-1390
Ransomware Unknown

CISA description

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

Required action

Apply updates per vendor instructions.