CVE-2021-38648 is an Elevation of Privilege vulnerability in Microsoft's Open Management Infrastructure (OMI), affecting various Azure services. With a CVSS score of 7.8 (HIGH), it allows a local, low-privileged attacker to gain full administrative privileges on vulnerable systems with low attack complexity. This vulnerability is actively exploited in the wild, with public exploit modules available, and has garnered significant community and media attention, indicating its critical nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_automation_state_configuration:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_automation_update_management:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_diagnostics_\(lad\):-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_open_management_infrastructure:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_security_center:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.