Sep 15, 2021
Critical Flaws Discovered in Azure App That Microsoft Secretly Installed on Linux VMs
Posted by Omuterema Akhahenda in categories: computing, security
“With a single packet, an attacker can become root on a remote machine by simply removing the authentication header.” ‘ Unfortunately, Microsoft can’t fix it for you. Users affected by these vulnerabilities must manually update the OMI agent to the patched versions.
Microsoft on Tuesday addressed a quartet of security flaws as part of its Patch Tuesday updates that could be abused by adversaries to target Azure cloud customers and elevate privileges as well as allow for remote takeover of vulnerable systems.
The list of flaws, collectively called OMIGOD by researchers from Wiz, affect a little-known software agent called Open Management Infrastructure that’s automatically deployed in many Azure services