CVE detail
CVE-2021-38647
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
20 source links · newest first
The 2022 Unit 42 Network Threat Trends Research Report includes an analysis of the CVEs most commonly exploited in 2021 and predictions for which CVEs attackers will likely focus on in the year to come.
vendorunit42.paloaltonetworks.comJul 21, 2022, 1:00 PMNetwork security trends observed November 2021 to January 2022 included high levels of cross-site scripting.
vendorunit42.paloaltonetworks.comMay 31, 2022, 7:00 PMNetwork attacks observed August-October 2021 included high levels of cross-site scripting, code execution and directory traversal.
vendorunit42.paloaltonetworks.comDec 21, 2021, 8:00 PMSo far, 2021 has proved to be somewhat of a security annus horribilis for tech giant Microsoft, with numerous vulnerabilities impacting several of its leading services, including Active Directory, Exchange, and Azure. Microsoft is no stranger to being targeted by attackers seeking to exploit known and zero-day vulnerabilities, but the rate and scale of the […]
newswww.csoonline.comOct 18, 2021, 9:00 AM- Security Affairs newsletter Round 335Security Affairs
A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the international press subscribe here. Previously undetected FontOnLake Linux malware used in targeted attacks Google addresses four high-severity flaws in Chrome Security […]
newssecurityaffairs.comOct 10, 2021, 1:07 PM - CVE-2021-38647 OMIGOD flaw impacts IBM QRadar AzureSecurity Affairs
Experts warn that CVE-2021-38647 OMIGOD flaws affect IBM QRadar Azure and can be exploited by remote attackers to execute arbitrary code. The Open Management Infrastructure RPM package in the IBM QRadar Azure marketplace images is affected by a remote code execution vulnerability tracked as CVE-2021-38647. CVE-2021-38647 is one of the four vulnerabilities in the Open […]
newssecurityaffairs.comOct 3, 2021, 3:16 PM Attackers are increasingly targeting a remote code execution vulnerability in the Open Management Infrastructure (OMI) framework that Microsoft released patches for earlier this month.
newswww.securityweek.comSep 21, 2021, 3:45 AM- 20th September – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 20th September, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has seen a global surge in the black market for fake COVID-19 vaccine certificates on Telegram, following US President Biden’s vaccine mandate announcements. The black market has expanded to […]
vendorresearch.checkpoint.comSep 19, 2021, 3:08 PM - Experts warn that Mirai Botnet starts exploiting OMIGOD flawSecurity Affairs
The Mirai botnet starts exploiting the recently disclosed OMIGOD vulnerability to compromise vulnerable systems exposed online. Threat actors behind a Mirai botnet starts exploiting a critical Azure OMIGOD vulnerability, tracked as CVE-2021-38647, a few days after Microsoft disclosed them. Recently released September 2021 Patch Tuesday security updates have addressed four severe vulnerabilities, collectively tracked as OMIGOD, in the Open Management […]
newssecurityaffairs.comSep 17, 2021, 8:22 PM Microsoft on Thursday published additional guidance on addressing recently disclosed vulnerabilities in the Open Management Infrastructure (OMI) framework, along with new protections to resolve the bugs within affected Azure Virtual Machine (VM) management extensions.
newswww.securityweek.comSep 17, 2021, 12:53 PMFour critical OMI vulnerabilities – one unauthorized RCE and three privilege escalation – were recently disclosed. Here’s how to remediate them.
vendorunit42.paloaltonetworks.comSep 16, 2021, 7:00 PMOverview On September 14, multiple vulnerabilities were discovered by researchers at Wiz.io. The most critical of them being CVE-2021-38647, now dubbed OMIGOD, which effects the Open Management Infrastructure (OMI) agent in versions 1.6.8.0 and below. Azure customers effected by this vulnerability are still vulnerable and must take manual action to ensure the OMI agent is updated. […]
exploithorizon3.aiSep 16, 2021, 2:01 PM- OMIGOD vulnerabilities expose thousands of Azure users to hackSecurity Affairs
OMIGOD – Microsoft addressed four vulnerabilities in the Open Management Infrastructure (OMI) software agent that could expose Azure users to attacks. Recently released September 2021 Patch Tuesday security updates have addressed four severe vulnerabilities, collectively tracked as OMIGOD, in the Open Management Infrastructure (OMI) software agent that exposes Azure users to attack. Below is the list of the […]
newssecurityaffairs.comSep 15, 2021, 6:17 PM Four of the fixes that Microsoft released as part of its September 2021 Patch Tuesday updates deal with vulnerabilities in the Open Management Infrastructure (OMI) software agent embedded in Azure services.
newswww.securityweek.comSep 15, 2021, 1:16 PMNo excerpt available.
Mitigationwww.cisa.govSep 15, 2021, 12:15 PM- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38647portal.msrc.microsoft.com
No excerpt available.
Vendor Advisoryportal.msrc.microsoft.comSep 15, 2021, 12:15 PM - http://packetstormsecurity.com/files/164694/Microsoft-OMI-Management-Interface-Authentication-Bypass.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comSep 15, 2021, 12:15 PM - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647msrc.microsoft.com
No excerpt available.
Vendor Advisorymsrc.microsoft.comSep 15, 2021, 12:15 PM - Microsoft Patch Tuesday fixes CVE-2021-40444 MSHTML zero-daySecurity Affairs
Microsoft Patch Tuesday security updates for September 2021 addressed a high severity zero-day flaw actively exploited in targeted attacks. Microsoft Patch Tuesday security updates for September 2021 addressed a high severity zero-day RCE actively exploited in targeted attacks aimed at Microsoft Office and Office 365 on Windows 10 computers. The flaw, tracked as CVE-2021-40444, resides in the MSHTML, […]
newssecurityaffairs.comSep 15, 2021, 5:03 AM On September 2021 Patch Tuesday, Microsoft has fixed 66 CVE-numbered vulnerabilities in a wide variety of its solutions. Of these, the most crucial to address is CVE-2021-40444, the remote code execution MSHTML vulnerability actively exploited by attackers via malicious MS Office documents. “After this bug was discovered and became public knowledge on September 7, security researchers and analysts began swapping proof-of-concept examples of how an attacker might leverage the exploit,” noted SophosLabs Principal Researcher Andrew … More →
newswww.helpnetsecurity.comSep 14, 2021, 6:47 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-38649CVSS 7.0 · High
Open Management Infrastructure Elevation of Privilege Vulnerability
KEV listed8 mentions - CVE-2021-38648CVSS 7.8 · High
Open Management Infrastructure Elevation of Privilege Vulnerability
KEV listed9 mentions - CVE-2021-38645CVSS 7.8 · High
Open Management Infrastructure Elevation of Privilege Vulnerability
KEV listed8 mentions - CVE-2022-29149CVSS 7.8 · High
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
- CVE-2024-21330CVSS 7.8 · High
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
- CVE-2024-21334CVSS 9.8 · Critical
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability