Fiche vulnérabilité
CVE-2021-38647 : faille exploitée microsoft azure automation state… (CVSS 9.8)
Description
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Oui, inscrite au catalogue CISA KEV
- Publication
- 15 sept. 2021
- Dernière mise à jour
- 10 août 2026
Produits concernés
- microsoft azure automation state configuration
- microsoft azure automation update management
- microsoft azure diagnostics \(lad\)
- microsoft azure security center
- microsoft azure sentinel
- microsoft azure stack hub
- microsoft container monitoring solution
- microsoft log analytics agent
- microsoft open management infrastructure
- microsoft system center operations manager
Correctif et mesures
Apply updates per vendor instructions.