« Volver al listado

CVE-2024-21330

Estado: AnalizadaAlta (7.8)—

Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (8)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-21330",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-21330",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-03-12T19:23:30.888206Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "System Center Operations Manager (SCOM) 2019",
          "versions": [
            {
              "status": "affected",
              "version": "10.19.0",
              "lessThan": "10.19.1253.0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "System Center Operations Manager (SCOM) 2022",
          "versions": [
            {
              "status": "affected",
              "version": "10.22.0",
              "lessThan": "10.22.1070.0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Azure Automation",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "OMS Agent for Linux GA 1.19.0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Azure Automation Update Management",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "OMS Agent for Linux GA v1.19.0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Azure Sentinel",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "OMS Agent for Linux GA v1.19.0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Container Monitoring Solution",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "microsoft-oms-latest with full ID: sha256:855bfeb0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Azure HDInsight",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "lessThan": "omi-1.8.1-0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Open Management Infrastructure",
          "versions": [
            {
              "status": "affected",
              "version": "16.0",
              "lessThan": "OMI version 1.8.1-0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Open Management Infrastructure",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "1.8.1-0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Azure Security Center",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "OMS Agent for Linux GA 1.19.0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Log Analytics Agent",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "OMS Agent for Linux GA v1.19.0",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        }
      ]
    }
  ],
  "published": "2024-03-12T17:15:49.143",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21330",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21330",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@microsoft.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability"
    },
    {
      "lang": "es",
      "value": "Infraestructura de gestión abierta (OMI) Vulnerabilidad de elevación de privilegios"
    }
  ],
  "lastModified": "2026-06-17T07:09:01.100",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:azure_automation:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D341E199-250C-47C7-ABE8-39973A5C63E0"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:azure_automation_update_management:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23A8B342-E863-4C71-9CE1-FB325FF34829"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:azure_security_center:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA1626DA-5B19-4291-B840-633EF458984C"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:azure_sentinel:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B80F8C3B-BEF9-43D5-9455-6C6F608CF519"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:container_monitoring_solution:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68A461E8-C834-4F97-98E3-516A191A3BAA"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:log_analytics_agent:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDAE892B-324C-45E3-BFA0-C2B7B6939F54"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:operations_management_suite_agent_for_linux:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1B6D6F4-F48C-482B-B54B-6962D6D506A9",
              "versionEndExcluding": "1.8.1-0"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:system_center_operations_manager:2019:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0BFD64D6-E8BB-4606-8D4C-EAE586CAD791"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:system_center_operations_manager:2022:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABD632BE-513E-4581-9C8C-3A13DA1ADF1F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}