Revisiting OMI: Analysis of CVE-2022-29149, a privilege escalation vulnerability in Azure OMI
ID: 0667db3a-6165-5b5c-b2e9-5eee6c1c677f
STIX ID: report--0667db3a-6165-5b5c-b2e9-5eee6c1c677f
Feed Name: Wiz Blog
**Executive summary:** Wiz researchers disclose and analyze CVE-2022-29149, a CVSS 7.8 local privilege escalation in Microsoft’s Open Management Infrastructure (OMI) used by numerous Azure services; they show that OMI's weak secretString generation makes it possible to predict and forge privileged inter-process messages to gain root, describe the patch and mitigation steps (update to OMI 1.6.9-1, enable Automatic Extension Upgrade, or migrate to Azure Monitoring Agent), and highlight the systemic risk of opaque cloud middleware agents while providing detection guidance and a community cloud-middleware dataset.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
