HT TECH wants to start sending you push notifications. Click allow to subscribe

OMIGOD! Microsoft has fixed some critical bugs in a secretly installed Azure Linux app

Four critical vulnerabilities have been addressed that are collectively known as OMIGOD.

By: HT TECH
Updated on: Sep 16 2021, 15:49 IST
These four vulnerabilities that Microsoft addressed were found by cloud security firm Wiz researchers Nir Ohfeld and Shir Tamari who named them “OMIGOD”. (Bleeping Computer )

Microsoft has managed to address four critical vulnerabilities that are collectively known as OMIGOD. These vulnerabilities were found in the Open Management Infrastructure (OMI) software agent that is silently installed on Azure Linus machines and accounts for more than half of Azure instances, as Bleeping Computer reported. OMI is a software service for IT management and supports most UNIX systems and modern Linux platforms. It is used by multiple Azure services including Open Management Suite (OMS), Azure Insights, Azure Automation, and others.

These four vulnerabilities that Microsoft addressed were found by cloud security firm Wiz researchers Nir Ohfeld and Shir Tamari who named them “OMIGOD”. "Problematically, this 'secret' agent is both widely used (because it is open source) and completely invisible to customers as its usage within Azure is completely undocumented," Ohfeld said.

You may be interested in

Laptops Tablets
15% OFF
Microsoft Surface Studio A1Y 00022
  • Platinum Silver
  • 16 GB LPDDR4X RAM
  • 512 GB SSD
₹190,046₹222,999
Buy now
7% OFF
Microsoft Surface Pro 8 8PV 00029
  • Graphite Black
  • 16 GB DDR4 RAM
  • 256 GB SSD
₹139,999₹149,999
Buy now
47% OFF
Microsoft Surface 4 5UI 00049
  • Platinum Silver
  • 8 GB DDR4 RAM
  • 256 GB SSD
₹98,000₹186,500
Buy now
2% OFF
Microsoft Surface Pro 7 M1866 VDH 00013
  • Platinum
  • 4 GB LPDDR4X RAM
  • 128 GB SSD
₹78,990₹80,999
Buy now
38% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹24,999₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
22% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,599₹24,990
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

Ohfeld and Tamari “conservatively estimate” that at least thousands of Azure customers and millions of endpoints have been impacted by these security flaws:

CVE-2021-38647 – Unauthenticated RCE as root (Severity: 9.8/10)

CVE-2021-38648 – Privilege Escalation vulnerability (Severity: 7.8/10)

CVE-2021-38645 – Privilege Escalation vulnerability (Severity: 7.8/10)

CVE-2021-38649 – Privilege Escalation vulnerability (Severity: 7.0/10)

According to reports, all Azure customers with Linux machines running one of the following tools or services are at risk:

- Azure Automation

- Azure Automatic Update

- Azure Operations Management Suite (OMS)

- Azure Log Analytics

- Azure Configuration Management

- Azure Diagnostics

"When users enable any of these popular services, OMI is silently installed on their Virtual Machine, running at the highest privileges possible," Ohfeld said adding that "this happens without customers’ explicit consent or knowledge. Users simply click agree to log collection during set-up and they have unknowingly opted in."

Other Microsoft customers have also been and can be impacted by the OMIGOD flaws since the OMI agent “can also be manually installed on-premise as it is built in the System Center for Linux, which is Microsoft's server management tool”.

"This is a textbook RCE vulnerability that you would expect to see in the 90’s – it’s highly unusual to have one crop up in 2021 that can expose millions of endpoints," Ohfeld explained regarding the CVE-2021-38647 RCE bug.

"With a single packet, an attacker can become root on a remote machine by simply removing the authentication header. It’s that simple. [T]his vulnerability can be also used by attackers to obtain initial access to a target Azure environment and then move laterally within it,” Ohfeld said.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 16 Sep, 15:49 IST

Sale

Laptops Tablets
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
9% OFF
Asus Vivobook K15 OLED K513EA L512TS Laptop
  • Indie Black
  • 16 GB RAM
  • 512 GB SSD
₹41,999₹45,999
Buy now
22% OFF
Asus ROG Strix G15 G512LI HN059T Laptop
  • Black
  • 8 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
26% OFF
Asus Zenbook 14 Flip OLED UP3404VA KN542WS Laptop
  • Ponder Blue
  • 16 GB RAM
  • 512 GB SSD
₹99,990₹134,990
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
38% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹28,999
Buy now
13% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹88,058₹101,398
Buy now
28% OFF
realme Pad 2 WiFi
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
NEXT ARTICLE BEGINS