PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-38647 Microsoft CVE debrief

CVE-2021-38647 is a Microsoft Open Management Infrastructure (OMI) remote code execution vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and marked it as having known ransomware campaign use, which makes it an urgent patching priority. CISA’s required action is to apply updates per vendor instructions.

Vendor
Microsoft
Product
Open Management Infrastructure (OMI)
CVSS
CRITICAL 9.8
CISA KEV
Listed
Original CVE published
2021-11-03
Original CVE updated
2021-11-03
Advisory published
2021-11-03
Advisory updated
2021-11-03

Who should care

Administrators and security teams responsible for Microsoft Open Management Infrastructure (OMI) deployments, especially those tracking CISA KEV items or ransomware risk.

Technical summary

The official record identifies this issue as a remote code execution vulnerability in Microsoft Open Management Infrastructure (OMI). The CISA KEV entry confirms it is known to be exploited in the wild and associates it with known ransomware campaign use. No additional technical details are provided in the supplied corpus.

Defensive priority

Urgent. This CVE is in CISA’s Known Exploited Vulnerabilities catalog, has known ransomware campaign use, and carried a CISA due date of 2021-11-17 for remediation.

Recommended defensive actions

  • Apply the vendor-recommended updates for Microsoft Open Management Infrastructure (OMI) as soon as possible.
  • Prioritize any exposed or externally reachable OMI deployments for immediate remediation.
  • Verify whether OMI systems are present in your environment and confirm they are covered by patch management.
  • Use the CISA KEV catalog as a trigger for incident response review and remediation tracking.
  • Reassess compensating controls and monitoring around systems running OMI until updates are applied.

Evidence notes

Source corpus shows the CVE record, the official CVE/NVD references, and the CISA KEV entry. CISA metadata states: vendorProject Microsoft, product Open Management Infrastructure (OMI), vulnerabilityName Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability, dateAdded 2021-11-03, dueDate 2021-11-17, knownRansomwareCampaignUse Known, and requiredAction Apply updates per vendor instructions.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-38647 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-38647

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-38647 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-38647

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.