Microsoft patched CVE-2022-29149, a CVSS 7.8 local privilege-escalation vulnerability in Open Management Infrastructure (OMI) versions earlier than 1.6.9-1. OMI, Linux/UNIX management middleware that can be installed through Azure monitoring and management agents, used a predictable time-based seed in its secretString authentication mechanism. A low-privileged local attacker could reconstruct the secret, forge privileged internal messages, and obtain root access, with high confidentiality, integrity, and availability impact.
Microsoft directed customers to update affected OMI installations and dependent Azure and System Center components, including agents, VM extensions, management packs, container images, and Azure Stack Hub extensions. Following researcher coordination, Microsoft expanded customer notifications and added Automatic Extension Upgrade support for OMS, Linux Azure Diagnostics, and Desired State Configuration agents; enabling it automatically updates bundled OMI. Organizations should inventory potentially silently deployed cloud-management agents, enable automatic extension upgrades where available, manually remediate unsupported deployments, and migrate to Azure Monitor Agent where feasible because it does not rely on OMI.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Microsoft announced Automatic Extension Upgrade support for the Azure Desired State Configuration extension for Linux. The DSCForLinux extension installs OMI and the DSC agent, and Microsoft recommended enabling automatic upgrades to receive security and performance updates.
Azure updated the MSRC advisory with additional vulnerability, affected-service, and remediation details. Microsoft also sent Azure Service Health Notifications to affected customers.
Microsoft released a Patch Tuesday fix for CVE-2022-29149, a CVSS 7.8 local privilege-escalation vulnerability affecting OMI versions earlier than 1.6.9-1. The fix updated OMI to version 1.6.9-1 and removed the vulnerable secretString mechanism.
The OMIGOD findings affecting Azure OMI, including a root-level remote command-execution flaw, were published. The research stated there was evidence of exploitation in the wild, and Microsoft released patches while customers initially had to update installations themselves.
Wiz reported four vulnerabilities in Microsoft's Open Management Infrastructure (OMI), including CVE-2021-38645 and CVE-2021-38647.
Microsoft onboarded the OMS, Azure Diagnostics/LAD, and DSC agents to Azure Automatic Extension Upgrade, allowing enabled agents and their bundled OMI components to receive updates automatically.
Wiz developed and validated a proof of concept for CVE-2022-29149, showing that OMI's predictable time-seeded secretString could be recreated to forge privileged messages and obtain root privileges. Wiz shared its findings on vulnerable OMI prevalence and remediation challenges with Microsoft and Azure.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
wiz.io
Open sourcewiz.io
Open sourcetechcommunity.microsoft.com
Open sourcetechcommunity.microsoft.com
Open sourcewiz.io
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.