Skip to main content

CVE detail

CVE-2021-38647

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CVSS 9.8 · CriticalBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
20 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 6 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
20 source links · newest first
  • The 2022 Unit 42 Network Threat Trends Research Report includes an analysis of the CVEs most commonly exploited in 2021 and predictions for which CVEs attackers will likely focus on in the year to come.

    vendorunit42.paloaltonetworks.comJul 21, 2022, 1:00 PM
  • Network security trends observed November 2021 to January 2022 included high levels of cross-site scripting.

    vendorunit42.paloaltonetworks.comMay 31, 2022, 7:00 PM
  • Network attacks observed August-October 2021 included high levels of cross-site scripting, code execution and directory traversal.

    vendorunit42.paloaltonetworks.comDec 21, 2021, 8:00 PM
  • So far, 2021 has proved to be somewhat of a security annus horribilis for tech giant Microsoft, with numerous vulnerabilities impacting several of its leading services, including Active Directory, Exchange, and Azure. Microsoft is no stranger to being targeted by attackers seeking to exploit known and zero-day vulnerabilities, but the rate and scale of the […]

    newswww.csoonline.comOct 18, 2021, 9:00 AM
  • Security Affairs newsletter Round 335Security Affairs

    A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the international press subscribe here. Previously undetected FontOnLake Linux malware used in targeted attacks Google addresses four high-severity flaws in Chrome Security […]

    newssecurityaffairs.comOct 10, 2021, 1:07 PM
  • Experts warn that CVE-2021-38647 OMIGOD flaws affect IBM QRadar Azure and can be exploited by remote attackers to execute arbitrary code. The Open Management Infrastructure RPM package in the IBM QRadar Azure marketplace images is affected by a remote code execution vulnerability tracked as CVE-2021-38647. CVE-2021-38647 is one of the four vulnerabilities in the Open […]

    newssecurityaffairs.comOct 3, 2021, 3:16 PM
  • Attackers are increasingly targeting a remote code execution vulnerability in the Open Management Infrastructure (OMI) framework that Microsoft released patches for earlier this month.

    newswww.securityweek.comSep 21, 2021, 3:45 AM
  • 20th September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 20th September, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has seen a global surge in the black market for fake COVID-19 vaccine certificates on Telegram, following US President Biden’s vaccine mandate announcements. The black market has expanded to […]

    vendorresearch.checkpoint.comSep 19, 2021, 3:08 PM
  • The Mirai botnet starts exploiting the recently disclosed OMIGOD vulnerability to compromise vulnerable systems exposed online. Threat actors behind a Mirai botnet starts exploiting a critical Azure OMIGOD vulnerability, tracked as CVE-2021-38647, a few days after Microsoft disclosed them. Recently released September 2021 Patch Tuesday security updates have addressed four severe vulnerabilities, collectively tracked as OMIGOD, in the Open Management […]

    newssecurityaffairs.comSep 17, 2021, 8:22 PM
  • Microsoft on Thursday published additional guidance on addressing recently disclosed vulnerabilities in the Open Management Infrastructure (OMI) framework, along with new protections to resolve the bugs within affected Azure Virtual Machine (VM) management extensions.

    newswww.securityweek.comSep 17, 2021, 12:53 PM
  • Four critical OMI vulnerabilities – one unauthorized RCE and three privilege escalation – were recently disclosed. Here’s how to remediate them.

    vendorunit42.paloaltonetworks.comSep 16, 2021, 7:00 PM
  • Overview On September 14, multiple vulnerabilities were discovered by researchers at Wiz.io. The most critical of them being CVE-2021-38647, now dubbed OMIGOD, which effects the Open Management Infrastructure (OMI) agent in versions 1.6.8.0 and below. Azure customers effected by this vulnerability are still vulnerable and must take manual action to ensure the OMI agent is updated. […]

    exploithorizon3.aiSep 16, 2021, 2:01 PM
  • OMIGOD – Microsoft addressed four vulnerabilities in the Open Management Infrastructure (OMI) software agent that could expose Azure users to attacks. Recently released September 2021 Patch Tuesday security updates have addressed four severe vulnerabilities, collectively tracked as OMIGOD, in the Open Management Infrastructure (OMI) software agent that exposes Azure users to attack. Below is the list of the […]

    newssecurityaffairs.comSep 15, 2021, 6:17 PM
  • Four of the fixes that Microsoft released as part of its September 2021 Patch Tuesday updates deal with vulnerabilities in the Open Management Infrastructure (OMI) software agent embedded in Azure services.

    newswww.securityweek.comSep 15, 2021, 1:16 PM
  • No excerpt available.

    Mitigationwww.cisa.govSep 15, 2021, 12:15 PM
  • No excerpt available.

    Vendor Advisoryportal.msrc.microsoft.comSep 15, 2021, 12:15 PM
  • No excerpt available.

    Exploitpacketstormsecurity.comSep 15, 2021, 12:15 PM
  • No excerpt available.

    Vendor Advisorymsrc.microsoft.comSep 15, 2021, 12:15 PM
  • Microsoft Patch Tuesday security updates for September 2021 addressed a high severity zero-day flaw actively exploited in targeted attacks. Microsoft Patch Tuesday security updates for September 2021 addressed a high severity zero-day RCE actively exploited in targeted attacks aimed at Microsoft Office and Office 365 on Windows 10 computers. The flaw, tracked as CVE-2021-40444, resides in the MSHTML, […]

    newssecurityaffairs.comSep 15, 2021, 5:03 AM
  • On September 2021 Patch Tuesday, Microsoft has fixed 66 CVE-numbered vulnerabilities in a wide variety of its solutions. Of these, the most crucial to address is CVE-2021-40444, the remote code execution MSHTML vulnerability actively exploited by attackers via malicious MS Office documents. “After this bug was discovered and became public knowledge on September 7, security researchers and analysts began swapping proof-of-concept examples of how an attacker might leverage the exploit,” noted SophosLabs Principal Researcher Andrew … More →

    newswww.helpnetsecurity.comSep 14, 2021, 6:47 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence