{
  "id": "CVE-2021-38648",
  "url": "https://spydr.io/cve/CVE-2021-38648",
  "published": "2021-09-15T12:15:15.147Z",
  "modified": "2026-08-10T20:15:31.087Z",
  "score": 7.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "microsoft.com",
  "epss": 0.11424,
  "epss_percentile": 0.95904,
  "exploited": true,
  "kev": {
    "added": "2021-11-03",
    "due": "2021-11-17",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-38648"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "Microsoft"
  ],
  "products": [
    "Microsoft Azure Automation State Configuration, DSC Extension",
    "Microsoft Azure Automation Update Management",
    "Microsoft Azure Diagnostics (LAD)",
    "Microsoft Azure Security Center",
    "Microsoft Azure Sentinel",
    "Microsoft Azure Stack Hub",
    "Microsoft Container Monitoring Solution",
    "Microsoft Log Analytics Agent",
    "Microsoft Open Management Infrastructure",
    "Microsoft System Center Operations Manager (SCOM)"
  ],
  "cwes": [],
  "description": "Open Management Infrastructure Elevation of Privilege Vulnerability",
  "status": "Analyzed",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38648",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "http://packetstormsecurity.com/files/164925/Microsoft-OMI-Management-Interface-Authentication-Bypass.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-38648",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-38648",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38648",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
