HIGH

CVE-2021-38648

Microsoft Azure Automation State Configuration 2021-09-15 CVSS v3.1
CVSS
7.8
KEV

Description

Open Management Infrastructure Elevation of Privilege Vulnerability

Summary dbcve.org

CVE-2021-38648 is an elevation of privilege vulnerability in Open Management Infrastructure (OMI), a open-source implementation of WBEM for Linux and Unix systems. The vulnerability allows a local attacker to gain higher privileges than initially granted, potentially leading to full system compromise.

Mitigation

Apply available patches for Open Management Infrastructure. If patching is not immediately possible, restrict local access to systems running OMI services and ensure least-privilege principles are enforced.

Proof of Concept
Patch Commit

EPSS Score

11.42%
Probability of exploitation in next 30 days
95.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE