CVE-2024-21334HighCVSS 9.8
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? A remote unauthenticated attacker could access the OMI instance from the Internet and send specially crafted requests to trigger a use-after-free vulnerability.
Is there any action customers need to take to protect themselves against this vulnerability? Customers running affected versions of SCOM (System Center Operations Manager) should update to OMI version 1.8.1-0.
🎯 Affected products3
- Open Management Infrastructure
- System Center Operations Manager (SCOM) 2019
- System Center Operations Manager (SCOM) 2022
✅ Remediation
KBRelease Notes (Security Update) — fixed build 10.19.1253.0 KBRelease Notes (Security Update) — fixed build 10.22.1070.0 KBRelease Notes (Security Update) — fixed build OMI version 1.8.1-0
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21334
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=58208
- patchhttps://www.microsoft.com/en-in/download/details.aspx?id=104213
- patchhttps://github.com/microsoft/omi-kits/tree/master/release
- referencehttps://github.com/microsoft/omi