logo

“Secret” Agent Exposes Azure Customers To Unauthorized Code Execution

ID: 75e1c1ab-dd8f-5b66-a2a2-677bee94e8c5

STIX ID: report--75e1c1ab-dd8f-5b66-a2a2-677bee94e8c5

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2021-09-14

Date Updated: 2026-05-01

...
...

**OMIGOD (September 2021)** — Wiz disclosed four critical zero-day vulnerabilities in the Open Management Infrastructure (OMI) agent used by numerous Azure services that allow local privilege escalation and a critical RCE (notably when management ports 5985/5986/1270 are exposed); Microsoft released patches and auto-update measures in mid-September 2021 but many instances required manual updates, and active exploitation by Mirai-style botnets and cryptominers was observed. The advisory lists affected services, detection commands, mitigation steps (including verifying OMI version 1.6.8.1 and restricting OMI network access), and emphasizes the supply-chain risk of silently deployed privileged agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.