CVE-2021-38645High· 7.8▾ Abyssal⚠ Exploited in the wildOpen Management Infrastructure Elevation of Privilege Vulnerability
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 0.5 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Nov 17, 2021
Last analysed / modified upstream
2.7%
Added to the CISA catalog on Nov 3, 2021. Federal remediation due Nov 17, 2021. View catalog ↗
Open Management Infrastructure Elevation of Privilege Vulnerability
azure_automation_state_configurationazure_automation_update_managementazure_diagnostics_(lad)azure_security_centerazure_sentinelazure_stack_hubcontainer_monitoring_solutionlog_analytics_agentopen_management_infrastructure < 1.6.8-1system_center_operations_managerUpgrade past the affected range:
open_management_infrastructure 1.6.8-1Connected by shared product, vendor, weakness, or advisory.
CVE-2021-38649High· 7.0Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38648High· 7.8Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38647Critical· 9.8Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81963High· 7.8Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-88097High· 8.1Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.