logo

Revisiting OMI: Analysis of CVE-2022-29149, a privilege escalation vulnerability in Azure OMI

ID: 0667db3a-6165-5b5c-b2e9-5eee6c1c677f

STIX ID: report--0667db3a-6165-5b5c-b2e9-5eee6c1c677f

Feed Name: Wiz Blog

Threat Score
70/100

Date Published: 2022-08-05

Date Updated: 2026-05-01

...
...

**Executive summary:** Wiz researchers disclose and analyze CVE-2022-29149, a CVSS 7.8 local privilege escalation in Microsoft’s Open Management Infrastructure (OMI) used by numerous Azure services; they show that OMI's weak secretString generation makes it possible to predict and forge privileged inter-process messages to gain root, describe the patch and mitigation steps (update to OMI 1.6.9-1, enable Automatic Extension Upgrade, or migrate to Azure Monitoring Agent), and highlight the systemic risk of opaque cloud middleware agents while providing detection guidance and a community cloud-middleware dataset.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.