Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

Multiple Critical Vulnerabilities in Azure VM Management Extensions

Issued: 
Wednesday, 29 September, 2021
Last Revision: 
Wednesday, 29 September, 2021
Vendor: 
Product: 
Severity Level: 
Summary: 

The vulnerabilities, which are collectively referred to as “OMIGOD,” are found within OMI agents that are installed on Microsoft’s Azure Linux virtual machines (VMs) by default.

 

An unauthenticated, remote attacker can exploit the vulnerability (CVE-2021-38647) by sending a specially crafted request to a vulnerable host over a publicly accessible remote management port (ports 5986, 5985 and 1270). Successful exploitation would grant an attacker the ability to execute arbitrary code with root privileges on the vulnerable Linux VM. 

 

As a result, CVE-2021-38647 vulnerability is the most severe out of the four flaws encompassing OMIGOD. We have already reported this vulnerability in Risk Directive R15092021000105 dated 15th Sep 21.

 

CVE-2021-38645, CVE-2021-38648 and CVE-2021-38649 are three elevation of privilege vulnerabilities in OMI.

 

 

CVE

                         Description 

CVSS3.0 Score

CVE-2021-38647

Open Management Infrastructure Remote Code Execution Vulnerability

9.8

CVE-2021-38645

Open Management Infrastructure Elevation of Privilege Vulnerability

7.8

CVE-2021-38648

Open Management Infrastructure Elevation of Privilege Vulnerability

7.8

CVE-2021-38649

Open Management Infrastructure Elevation of Privilege Vulnerability

7.0

 

                                                                                                    Table 1: Vulnerability details 

 

OMI Overview:

Open Management Infrastructure (OMI) is an open-source Web-Based Enterprise Management (WBEM) implementation for managing Linux and UNIX systems. Several Azure Virtual Machine (VM) management extensions use this framework to orchestrate configuration management and log collection on Linux VMs.

 

 

  Vulnerability / CVE

                Affected Product(s)

CVE-2021-38647

CVE-2021-38645

CVE-2021-38648

CVE-2021-38649

Azure Stack Hub

Azure Sentinel

Azure Security Center

Container Monitoring Solution

Azure Diagnostics (LAD)

Log Analytics Agent

Azure Automation Update Management

Azure Automation State Configuration, DSC Extension

System Center Operations Manager (SCOM)

Azure Open Management Infrastructure

 

                                                                                                     Table 2: Vulnerable versions

Recommendation: 

Please apply the patches released in Sept 21 and refer the references for additional protection, to know the version of vulnerable OMI, PaaS service affected by OMI vulnerability and determine impacted VMs by these vulnerabilities.