Researchers disclosed OMIGOD, a set of four vulnerabilities in Microsoft’s Open Management Infrastructure (OMI), a management service broadly deployed on Azure Linux virtual machines. The most severe issue, CVE-2021-38647, allows unauthenticated remote code execution via a crafted HTTP request, enabling attackers to run commands as the OMI agent user, which is commonly root on affected systems.
The flaws affect OMI versions earlier than 1.6.8-1, putting large numbers of Azure customers at risk where the service is exposed. Public proof-of-concept material and a Docker-based demo environment were released to help defenders validate exposure and generate indicators of compromise, while remediation guidance calls for upgrading to 1.6.8-1 or later.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Wiz Research Team published research describing four vulnerabilities in Open Management Infrastructure (OMI), including CVE-2021-38647, and said they were easy to exploit. The flaws could enable arbitrary remote code execution and privilege escalation to root on affected Azure Linux systems using OMI.
A GitHub project published a reproducible Docker-based lab and proof of concept for CVE-2021-38647 to help defenders validate exposure and generate indicators of compromise. The project demonstrates command execution and a reverse shell as root against a vulnerable OMI target.
A patched OMI release was made available to remediate the disclosed vulnerabilities, with the content stating that versions below 1.6.8-1 are vulnerable. Defenders are advised to upgrade to OMI version 1.6.8.1 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.