HIGH
CVE-2021-38645
CVSS
7.8
KEV
Description
Open Management Infrastructure Elevation of Privilege Vulnerability
Summary dbcve.org
This is an elevation of privilege vulnerability in Open Management Infrastructure (OMI), a widely-used infrastructure management framework. The vulnerability allows an attacker to gain higher-level permissions on affected systems.
Mitigation
Apply the security updates provided by Microsoft for Open Management Infrastructure. If patches are unavailable, restrict network access to OMI management ports and follow the principle of least privilege.
EPSS Score
2.73%
Probability of exploitation in next 30 days
85.5th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38645
Patch, Vendor Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38645
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38645
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.