CVE-2021-38648: high-severity vulnerability in Microsoft Open Management Infrastructure
Open Management Infrastructure Elevation of Privilege Vulnerability
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
A vulnerability in Open Management Infrastructure allows an authenticated attacker to escalate their privileges to a higher level of system access. This is dangerous because it enables unauthorized administrative control over the affected system.
This elevation of privilege vulnerability in OMI allows authenticated local users to gain elevated system privileges through insufficient access controls. The attack requires prior authentication and successful exploitation grants attacker elevated privileges on the target system.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.