logo

Understanding the impact of OMIGOD (CVE-2021-38647)

ID: 7f359618-ddad-509d-9983-3f639906d717

STIX ID: report--7f359618-ddad-509d-9983-3f639906d717

Feed Name: Censys Blog

Threat Score
78/100

Date Published: 2021-09-17

Date Updated: 2026-04-27

...
...

Censys details a critical vulnerability in Microsoft OMI (CVE-2021-38647) that allows unauthenticated remote command execution as root. The report includes proof-of-concept exploit demonstrations, a Docker-based vulnerable environment for testing, guidance on reliable scanning (Content-Type header requirement), evidence of mass scanning, and identification of 101 internet-exposed hosts; immediate patching is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.