New Blog Post | ASC to find machines affected OMI vulnerabilities in Azure VM Management Extension

%3CLINGO-SUB%20id%3D%22lingo-sub-2767936%22%20slang%3D%22en-US%22%3ENew%20Blog%20Post%20%7C%20ASC%20to%20find%20machines%20affected%20OMI%20vulnerabilities%20in%20Azure%20VM%20Management%20Extension%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2767936%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22AshleyMartin_0-1632157489239.gif%22%20style%3D%22width%3A%20705px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F311613iE706476DEE037DF7%2Fimage-dimensions%2F705x476%3Fv%3Dv2%22%20width%3D%22705%22%20height%3D%22476%22%20role%3D%22button%22%20title%3D%22AshleyMartin_0-1632157489239.gif%22%20alt%3D%22AshleyMartin_0-1632157489239.gif%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-security-center%2Fusing-asc-to-find-machines-affected-by-omi-vulnerabilities-in%2Fba-p%2F2767240%22%20target%3D%22_blank%22%3EUsing%20ASC%20to%20find%26nbsp%3Bmachines%20affected%20by%20OMI%20vulnerabilities%20in%20Azure%20VM%20Management%20Extensions%20-%20Microsoft%20Tech%20Community%3C%2FA%3E%3C%2FP%3E%0A%3CP%3ETwo%20weeks%20ago%2C%26nbsp%3BMicrosoft%20released%20fixes%20for%20three%20Elevation%20of%20Privilege%20(EoP)%20vulnerabilities%20and%20one%20unauthenticated%20Remote%20Code%20Execution%20(RCE)%20vulnerability%20in%20the%20Open%20Management%20Infrastructure%20(OMI)%20framework%3A%26nbsp%3B%20CVE-2021-38645%2C%20CVE-2021-38649%2C%20CVE-2021-38648%2C%20and%20CVE-2021-38647%2C%20respectively.%26nbsp%3B%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOMI%20is%20an%20open-source%20Web-Based%20Enterprise%20Management%20(WBEM)%20implementation%20for%20managing%20Linux%20and%20UNIX%20systems.%20Several%20Azure%20Virtual%20Machine%20(VM)%20management%20extensions%20use%20this%20framewor%20to%20orchestrate%20configuration%20management%20and%20log%20collection%20on%20Linux%20VMs.%20The%20remote%20code%20execution%20vulnerability%2C%26nbsp%3BCVE-2021-38647%2C%26nbsp%3Bonly%20impacts%20customers%20using%20a%20Linux%20management%20solution%20(on-premises%20SCOM%20or%20Azure%20Automation%20State%20Configuration%20or%20Azure%20Desired%20State%20Configuration%20extension)%20that%20enables%20remote%20OMI%20management.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOriginal%20Post%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fsecurity-compliance-and-identity%2Fnew-blog-post-asc-to-find-machines-affected-omi-vulnerabilities%2Fm-p%2F2767911%23M6345%22%20target%3D%22_blank%22%3ENew%20Blog%20Post%20%7C%20ASC%20to%20find%20machines%20affected%20OMI%20vulnerabilities%20in%20Azure%20VM%20Management%20Extension%20-%20Microsoft%20Tech%20Community%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2767936%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Security%20Center%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ECloud%20Security%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

AshleyMartin_0-1632157489239.gif

Using ASC to find machines affected by OMI vulnerabilities in Azure VM Management Extensions - Micro...

Two weeks ago, Microsoft released fixes for three Elevation of Privilege (EoP) vulnerabilities and one unauthenticated Remote Code Execution (RCE) vulnerability in the Open Management Infrastructure (OMI) framework:  CVE-2021-38645, CVE-2021-38649, CVE-2021-38648, and CVE-2021-38647, respectively.   

 

OMI is an open-source Web-Based Enterprise Management (WBEM) implementation for managing Linux and UNIX systems. Several Azure Virtual Machine (VM) management extensions use this framewor to orchestrate configuration management and log collection on Linux VMs. The remote code execution vulnerability, CVE-2021-38647, only impacts customers using a Linux management solution (on-premises SCOM or Azure Automation State Configuration or Azure Desired State Configuration extension) that enables remote OMI management.  

Original Post: New Blog Post | ASC to find machines affected OMI vulnerabilities in Azure VM Management Extension -...

0 Replies
www.000webhost.com