{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftcontainer_monitoring_solution-/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:microsoft:azure_automation_state_configuration:-:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:azure_automation_update_management:-:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:azure_diagnostics_\\(lad\\):-:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:azure_security_center:-:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:azure_sentinel:-:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:azure_stack_hub:-:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:container_monitoring_solution:-:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:log_analytics_agent:-:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:open_management_infrastructure:*:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:system_center_operations_manager:-:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2021-38647"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Open Management Infrastructure (all versions)","Azure Automation State Configuration (all versions)","Azure Automation Update Management (all versions)","Azure Diagnostics (all versions)","Azure Security Center (all versions)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","cloud","omi","omigod"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eCVE-2021-38647, commonly referred to as OMIGOD, is a critical authentication bypass vulnerability within the Open Management Infrastructure (OMI) framework. OMI is an open-source management interface frequently deployed across Microsoft Azure services. The vulnerability manifests due to improper validation of the Authorization header in incoming requests. Remote, unauthenticated attackers can exploit this flaw by sending specifically crafted SOAP requests to the OMI management service, which runs on ports 1270, 5985, or 5986. By omitting the Authorization header entirely, an attacker can invoke administrative methods, most notably the ExecuteScript method, to achieve remote code execution with root privileges on the target system. The recent surfacing of functional proof-of-concept code on public platforms increases the risk to unpatched infrastructure globally. Given the widespread integration of OMI in Azure management components, defenders must prioritize identifying and patching instances where this framework is active.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify systems running the OMI management service, typically listening on TCP ports 1270, 5985, or 5986.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious SOAP request targeted at the /wsman endpoint, specifically designed to invoke the ExecuteScript method within the SCX_OperatingSystem namespace.\u003c/li\u003e\n\u003cli\u003eAttacker omits the mandatory Authorization header from the HTTP request, exploiting the flawed logic in the OMI authentication handler.\u003c/li\u003e\n\u003cli\u003eThe OMI service receives the request and, due to the missing header, erroneously processes the request as if it were authenticated by a trusted user.\u003c/li\u003e\n\u003cli\u003eThe OMI service passes the provided Script argument, often Base64 encoded, to the underlying operating system for execution.\u003c/li\u003e\n\u003cli\u003eThe shell script executes with high-level privileges (root) on the target host.\u003c/li\u003e\n\u003cli\u003eAttacker receives the output of the executed commands via the HTTP response body from the OMI service, confirming successful exploitation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2021-38647 grants an attacker full remote code execution capabilities with root privileges. This impact extends across several critical Microsoft Azure services, including Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics, and Azure Security Center. Compromise allows for total system takeover, data exfiltration, and the ability to pivot laterally within the Azure environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all vulnerable instances of Open Management Infrastructure (OMI) to the latest patched version provided by Microsoft to eliminate the underlying vulnerability.\u003c/li\u003e\n\u003cli\u003eDeploy network-based detection to monitor for HTTP requests to ports 1270, 5985, or 5986 that lack an 'Authorization' header.\u003c/li\u003e\n\u003cli\u003eImplement the Zeek detection package provided by Corelight, which specifically looks for missing 'Authorization' headers in WSMAN traffic.\u003c/li\u003e\n\u003cli\u003eEnable detailed logging for WSMAN traffic to identify requests containing 'ExecuteScript' payloads within the SOAP body.\u003c/li\u003e\n\u003cli\u003eUse the provided Zeek notification logic to audit for successful 'EXPLOIT_RESPONSE' events that return command output (e.g., 'uid=0(root)').\u003c/li\u003e\n\u003cli\u003eBlock inbound traffic to OMI management ports from untrusted networks at the perimeter firewall.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T18:04:26Z","date_published":"2026-09-13T18:04:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-omigod/","summary":"Publicly available proof-of-concept exploits for CVE-2021-38647 allow unauthenticated remote command execution via the OMI framework by omitting the Authorization header.","title":"Exploitation of CVE-2021-38647 (OMIGOD) in Open Management Infrastructure","url":"https://feed.craftedsignal.io/briefs/2026-09-omigod/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:microsoft:container_monitoring_solution:-:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}