CVE-2021-38647Critical· 9.8▾ Hadal⚠ Exploited in the wildPoC availableOpen Management Infrastructure (OMI) Remote Code Execution Vulnerability
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 20 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Nov 17, 2021
Last analysed / modified upstream
100%
12 GitHub repos · Metasploit ×1 · Nuclei ×1
Added to the CISA catalog on Nov 3, 2021. Federal remediation due Nov 17, 2021. View catalog ↗
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
azure_automation_state_configurationazure_automation_update_managementazure_diagnostics_(lad)azure_security_centerazure_sentinelazure_stack_hubcontainer_monitoring_solutionlog_analytics_agentopen_management_infrastructure < 1.6.8-1system_center_operations_managerUpgrade past the affected range:
open_management_infrastructure 1.6.8-1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-38648High· 7.8Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38649High· 7.0Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2021-38645High· 7.8Open Management Infrastructure Elevation of Privilege Vulnerability
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-81963High· 7.8Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2026-83991Medium· 5.5Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.