“Secret” Agent Exposes Azure Customers To Unauthorized Code Execution
ID: 75e1c1ab-dd8f-5b66-a2a2-677bee94e8c5
STIX ID: report--75e1c1ab-dd8f-5b66-a2a2-677bee94e8c5
Feed Name: Wiz Blog
**OMIGOD (September 2021)** — Wiz disclosed four critical zero-day vulnerabilities in the Open Management Infrastructure (OMI) agent used by numerous Azure services that allow local privilege escalation and a critical RCE (notably when management ports 5985/5986/1270 are exposed); Microsoft released patches and auto-update measures in mid-September 2021 but many instances required manual updates, and active exploitation by Mirai-style botnets and cryptominers was observed. The advisory lists affected services, detection commands, mitigation steps (including verifying OMI version 1.6.8.1 and restricting OMI network access), and emphasizes the supply-chain risk of silently deployed privileged agents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
