Overview
- Description
- Open Management Infrastructure Remote Code Execution Vulnerability
- Source
- secure@microsoft.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Known exploits
Data from CISA
- Vulnerability name
- Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
- Exploit added on
- Nov 3, 2021
- Exploit action due
- Nov 17, 2021
- Required action
- Apply updates per vendor instructions.
Weaknesses
- nvd@nist.gov
- CWE-287
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:azure_automation_state_configuration:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DEC617A6-F1BC-44DE-A9BB-BECF2E788B0E" }, { "criteria": "cpe:2.3:a:microsoft:azure_automation_update_management:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23A8B342-E863-4C71-9CE1-FB325FF34829" }, { "criteria": "cpe:2.3:a:microsoft:azure_diagnostics_\\(lad\\):-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37AC51D6-F6F3-45D8-91E7-6EDD01C0273E" }, { "criteria": "cpe:2.3:a:microsoft:azure_open_management_infrastructure:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8477F336-71BB-4C49-A4EB-E1BC1EFF2F49" }, { "criteria": "cpe:2.3:a:microsoft:azure_security_center:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BA1626DA-5B19-4291-B840-633EF458984C" }, { "criteria": "cpe:2.3:a:microsoft:azure_sentinel:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B80F8C3B-BEF9-43D5-9455-6C6F608CF519" }, { "criteria": "cpe:2.3:a:microsoft:azure_stack_hub:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B457DA44-AD83-4E5C-B180-8A227462EC60" }, { "criteria": "cpe:2.3:a:microsoft:container_monitoring_solution:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "68A461E8-C834-4F97-98E3-516A191A3BAA" }, { "criteria": "cpe:2.3:a:microsoft:log_analytics_agent:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FDAE892B-324C-45E3-BFA0-C2B7B6939F54" }, { "criteria": "cpe:2.3:a:microsoft:system_center_operations_manager:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79983385-D5FE-4F76-924C-A2AA7E5BAAE8" } ], "operator": "OR" } ] } ]