HIGH
CVE-2021-38648
CVSS
7.8
KEV
Description
Open Management Infrastructure Elevation of Privilege Vulnerability
Summary dbcve.org
CVE-2021-38648 is an elevation of privilege vulnerability in Open Management Infrastructure (OMI), a open-source implementation of WBEM for Linux and Unix systems. The vulnerability allows a local attacker to gain higher privileges than initially granted, potentially leading to full system compromise.
Mitigation
Apply available patches for Open Management Infrastructure. If patching is not immediately possible, restrict local access to systems running OMI services and ensure least-privilege principles are enforced.
EPSS Score
11.42%
Probability of exploitation in next 30 days
95.9th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38648
Patch, Vendor Advisory
http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html
Exploit, Third Party Advisory, VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648
Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38648
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.