CRITICAL

CVE-2021-38647

Microsoft Azure Automation State Configuration 2021-09-15 CVSS v3.1
CVSS
9.8
KEV

Description

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Summary dbcve.org

CVE-2021-38647 is a critical remote code execution vulnerability in Open Management Infrastructure (OMI), an open-source implementation of WBEM used in Azure and Windows management tools. The flaw allows unauthenticated attackers to execute arbitrary code via specially crafted HTTP requests to the OMI management server.

Mitigation

Immediately patch or upgrade OMI agents on all affected systems to the latest secure version, prioritizing internet-facing and production systems. If patching is not immediately possible, consider network segmentation or disabling OMI where not required.

Proof of Concept
Patch Commit

EPSS Score

99.93%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE