CVE-2022-29149 is an Elevation of Privilege vulnerability in Open Management Infrastructure (OMI) affecting numerous Microsoft Azure services and components. With a CVSS score of 7.8 (HIGH), this vulnerability allows a local, low-privileged attacker to achieve high confidentiality, integrity, and availability impact with low attack complexity. While not actively exploited in the wild (no KEV entry) and lacking public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, including a detailed analysis by Wiz.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_automation_state_configuration:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_automation_update_management:-:*:*:*:*:*:*:* | ||
>= 3.0, < 3.0.137CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_diagnostics:*:*:*:*:*:*:*:* | ||
>= 4.0, < 4.0.27CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_diagnostics:*:*:*:*:*:*:*:* | ||
< 1.14.13CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_security_center:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.