Azure Open Management Infrastructure
CVE-2021-38647 — Open Management Infrastructure Remote Code Execution Vulnerability
Executive Summary
None
Overview
9.8
CVSS CRITICAL
Critical
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 8.5
EPSS Score
0.99933
probability of exploitation in the next 30 days
0.99969 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
9 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Azure Automation State Configuration, DSC Extension | Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Azure Automation Update Management | Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Azure Diagnostics (LAD) | Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Azure Security Center | Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Azure Sentinel | Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Azure Stack Hub Release Notes (Security Update) Release Notes (Security Update) Critical Remote Code Execution Base: 9.8 Temporal: 8.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C Monitor, Update and Config Mgmnt 1.14.01 3.1.135 Maybe None Container Monitoring Solution | Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Log Analytics Agent | Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Open Management Infrastructure | Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| System Center Operations Manager (SCOM) | Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
Patches
1 patch
| Article | Type | Restart |
|---|---|---|
Release Notes |
Security Update | Maybe |
Exploits & PoC
12 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| horizon3ai/CVE-2021-38647 | 233 | 2021-09-16 | Proof on Concept Exploit for CVE-2021-38647 (OMIGOD) |
| AlteredSecurity/CVE-2021-38647 | 67 | 2021-09-20 | CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD |
| marcosimioni/omigood | 20 | 2021-09-16 | OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team, specifically CVE-2021-38647. |
| midoxnet/CVE-2021-38647 | 8 | 2021-09-15 | CVE-2021-38647 POC for RCE |
| corelight/CVE-2021-38647 | 5 | 2021-09-15 | CVE-2021-38647 AKA "OMIGOD" vulnerability in Windows OMI |
| SimenBai/CVE-2021-38647-POC-and-Demo-environment | 3 | 2021-09-19 | OMIGod / CVE-2021-38647 POC and Demo environment |
| Immersive-Labs-Sec/cve-2021-38647 | 2 | 2021-09-16 | A PoC exploit for CVE-2021-38647 RCE in OMI |
| craig-m-unsw/omigod-lab | 1 | 2021-09-18 | A Vagrant VM test lab to learn about CVE-2021-38647 in the Open Management Infrastructure agent (aka "omigod"). |
| Vulnmachines/OMIGOD_cve-2021-38647 | 1 | 2021-09-24 | CVE-2021-38647 is an unauthenticated RCE vulnerability effecting the OMI agent as root. |
| goofsec/omigod | 1 | 2021-09-26 | Quick and dirty CVE-2021-38647 (Omigod) exploit written in Go. |
| abousteif/cve-2021-38647 | 0 | 2021-09-22 | https://github.com/corelight/CVE-2021-38647 without the bloat |
| corelight/CVE-2021-38647-noimages | 0 | 2024-03-13 |
Detection Rules
Detection availableCommunity detection & vulnerability-scanning rules aggregated from Sigma and Nuclei templates. Validate and tune to your environment before deploying.
Sigma rules 1
Nuclei templates 1
nuclei -id CVE-2021-38647
Acknowledgments
References
On This Page