PatchSiren cyber security CVE debrief
CVE-2021-38647 Microsoft CVE debrief
CVE-2021-38647 is a Microsoft Open Management Infrastructure (OMI) remote code execution vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and marked it as having known ransomware campaign use, which makes it an urgent patching priority. CISA’s required action is to apply updates per vendor instructions.
- Vendor
- Microsoft
- Product
- Open Management Infrastructure (OMI)
- CVSS
- CRITICAL 9.8
- CISA KEV
- Listed
- Original CVE published
- 2021-11-03
- Original CVE updated
- 2021-11-03
- Advisory published
- 2021-11-03
- Advisory updated
- 2021-11-03
Who should care
Administrators and security teams responsible for Microsoft Open Management Infrastructure (OMI) deployments, especially those tracking CISA KEV items or ransomware risk.
Technical summary
The official record identifies this issue as a remote code execution vulnerability in Microsoft Open Management Infrastructure (OMI). The CISA KEV entry confirms it is known to be exploited in the wild and associates it with known ransomware campaign use. No additional technical details are provided in the supplied corpus.
Defensive priority
Urgent. This CVE is in CISA’s Known Exploited Vulnerabilities catalog, has known ransomware campaign use, and carried a CISA due date of 2021-11-17 for remediation.
Recommended defensive actions
- Apply the vendor-recommended updates for Microsoft Open Management Infrastructure (OMI) as soon as possible.
- Prioritize any exposed or externally reachable OMI deployments for immediate remediation.
- Verify whether OMI systems are present in your environment and confirm they are covered by patch management.
- Use the CISA KEV catalog as a trigger for incident response review and remediation tracking.
- Reassess compensating controls and monitoring around systems running OMI until updates are applied.
Evidence notes
Source corpus shows the CVE record, the official CVE/NVD references, and the CISA KEV entry. CISA metadata states: vendorProject Microsoft, product Open Management Infrastructure (OMI), vulnerabilityName Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability, dateAdded 2021-11-03, dueDate 2021-11-17, knownRansomwareCampaignUse Known, and requiredAction Apply updates per vendor instructions.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-38647 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-38647
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-38647 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-38647
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.