AzureIncident TeardownsRetrospectives

OMIGOD (Sept 2021): Hidden Azure Agents Running as Root

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2021, written in 2026 with the benefit of hindsight.

In September 2021, Wiz researchers disclosed OMIGOD, four vulnerabilities in Open Management Infrastructure (OMI), a software agent that Microsoft silently installed on many Linux virtual machines in Azure when customers enabled certain services.

What OMI was

OMI is an open-source agent, similar in role to Windows Management Instrumentation, used by Azure services such as Log Analytics, Azure Automation, Azure Diagnostics and Azure Security Center to manage and monitor Linux VMs. Many customers didn't know it was installed — it was deployed automatically as part of enabling those services.

What the flaw allowed

The most severe vulnerability, CVE-2021-38647, allowed unauthenticated remote code execution as root by sending a request without an authentication header — if the OMI management ports were exposed. Other flaws allowed local privilege escalation to root.

The response

Microsoft released a patched OMI version, but because the agent was installed by various extensions, customers often had to update it themselves or wait for extensions to update. Attackers began scanning for exposed OMI ports and exploiting them, including for crypto mining, within days of disclosure.

Why it mattered

OMIGOD highlighted a blind spot in shared responsibility: provider-installed software running on customer VMs. Customers were responsible for patching their VMs but didn't know this agent existed. Microsoft was responsible for the software but not for updating it on every VM.

Lessons in hindsight

  • Inventory all agents and extensions on your VMs, including provider-installed ones.
  • Restrict management ports with network security groups.
  • Monitor vulnerability findings for agent software, not just operating systems.
  • Ask providers how their agents are updated.

Azure later improved extension management and moved monitoring to the newer Azure Monitor Agent, but the principle remains.

omigod vulnerabilityOMIGOD2021

More on this story