News: 1631854690

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

WTF? Microsoft makes fixing deadly OMIGOD flaws on Azure your job

(2021/09/17)


Microsoft Azure users running Linux VMs in the IT giant's Azure cloud need to take action to protect themselves against the four "OMIGOD" bugs in the Open Management Infrastructure (OMI) framework, because Microsoft hasn't raced to do it for them.

As The Register [1]outlined in our report on this month's Patch Tuesday release, Microsoft included fixes for [2]flaws security outfit Wiz spotted in Redmond's [3]open-source OMI agents. Wiz named the four flaws OMIGOD because they are astonishing.

The least severe of the flaws is rated 7/10 on the Common Vulnerability Scoring System. The worst is rated critical at 9.8/10.

[4]

Complicating matters is that running OMI is not something Azure users actively choose.

[5]

[6]

As Wiz explained: "When customers set up a Linux virtual machine in [Azure], the OMI agent is automatically deployed without their knowledge when they enable certain Azure services.

"Unless a patch is applied, attackers can easily exploit these four vulnerabilities to escalate to root privileges and remotely execute malicious code (for instance, encrypting files for ransom)."

[7]

Faced with that threat, it seems reasonable to expect that Microsoft would fix all the OMI agents it deploys and update VMs running vulnerable versions. That's the sort of thing cloud operators usually do – and do quietly before flaws are made public, so that attackers don't go to town.

Microsoft hasn't done so on this occasion. Indeed, the super-corp has kept deploying known bad versions of OMI when users create new Linux VMs.

[8]Microsoft's end-of-summer software security cleanse crushes more than 80 bugs

[9]Azure's now-fixed Cosmos DB flaw could have been exploited to read, write any database

[10]All your DNS were belong to us: AWS and Google Cloud shut down spying vulnerability

The Windows goliath's [11]latest advice , dated September 16, is: "Customers must update vulnerable extensions for their Cloud and On-Premises deployments as the updates become available per schedule outlined in table below."

Bad formatting means the table is wider than the section of Microsoft's web page, so rather a lot of lateral and vertical scrolling is required to learn that automatic updates have been enabled for six of the Azure services impacted by the bugs. But another seven services require manual updates. And even then, the automatic updates are a gradual rollout over the course of this month and not immediate.

It's on you to make sure you're running the latest OMI software in your Linux guests; a vulnerable build may have been injected into the virtual machine if you enabled certain services (see the aforementioned table.)

[12]

Understandably, Microsoft's actions – or lack thereof – have not gone down well.

They’ve also failed to update their own systems in Azure to install the patched version on new VM deployments. It’s honestly jaw dropping. — Kevin Beaumont (@GossiTheDog) [13]September 16, 2021

The Windows giant publicly fixed the holes in its OMI source [14]in mid-August , released it [15]last week , and only now is advising customers.

Researchers quickly found unpatched instances of OMI.

Security vendor Censys, for example, [16]wrote that it discovered "56 known exposed services worldwide that are likely vulnerable to this issue, including a major health organization and two major entertainment companies."

Happily, the biz also found "mass external exposure as seen with other hosts in the past (Microsoft Exchange comes to mind) does not appear to be present in this case."

In other words, there may not be that many vulnerable machines facing the public internet, or not many that are easily found. "The small footprint can be associated with nuances of how the OMI service responds, and that exposing OMI to the Internet likely requires deliberate effort," Censys noted.

Focus instead then will be on Microsoft's approach to patching and redeploying its open-source code.

That all said, the method needed to exploit the remote-code execution flaw is rather simple. We've already had sight of public proof-of-concept exploit code.

Sophos's [17]description of the flaw explains the peril:

Astonishingly, the bug seems to boil down to a laughably easy trick.

Rather than guessing a valid authentication token to insert into a fraudulent OMI web request, you simply omit all mention of the authentication token altogether, and you’re in!

Your next step is therefore obvious: patch ASAP. Because, as Censys puts it, "these issues would easily allow compromise with the highest-level privileges possible into any host which is running OMI." ®

Get our [18]Tech Resources



[1] https://www.theregister.com/2021/09/15/microsoft_patch_tuesday/

[2] https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution?s=09

[3] https://github.com/microsoft/omi

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YURnVCif0M1EfcA5lj5LdwAAAYU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YURnVCif0M1EfcA5lj5LdwAAAYU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YURnVCif0M1EfcA5lj5LdwAAAYU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YURnVCif0M1EfcA5lj5LdwAAAYU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2021/09/15/microsoft_patch_tuesday/

[9] https://www.theregister.com/2021/08/27/chaos_db_azure_cosmos_flaw/

[10] https://www.theregister.com/2021/08/06/aws_google_dns/

[11] https://msrc-blog.microsoft.com/2021/09/16/additional-guidance-regarding-omi-vulnerabilities-within-azure-vm-management-extensions/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YURnVCif0M1EfcA5lj5LdwAAAYU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://twitter.com/GossiTheDog/status/1438637187717816323?ref_src=twsrc%5Etfw

[14] https://github.com/microsoft/omi/commit/4ce2cf1cb0aa656b8eb934c5acc3f4d6a6796bfa

[15] https://github.com/microsoft/omi/releases/tag/v1.6.8-1

[16] https://censys.io/blog/understanding-the-impact-of-omigod-cve-2021-38647/

[17] https://nakedsecurity.sophos.com/2021/09/16/omigod-an-exploitable-hole-in-microsoft-open-source-code/

[18] https://whitepapers.theregister.com/



"fixing deadly OMIGOD flaws on Azure your job"

Mike 137

So one of the much hyped benefits of cloud (expert security off your hands) is no longer the case. Not surprising really. What many folks don't understand is that cloud services are not hugely profitable on an individual customer basis. The value comes from volume. Consequently, any service that's used by the majority is supported strongly, but services used by only a few don't get the same attention. That's actually the same as in practically every large scale big customer base business.

Re: "fixing deadly OMIGOD flaws on Azure your job"

A random security guy

And every security issue on the cloud is at once a major issue.

Re: "fixing deadly OMIGOD flaws on Azure your job"

MyffyW

Ah "responsibilities that remain with the customer" ... it's the Calrissian conjecture of cloud hosting.

Re: "fixing deadly OMIGOD flaws on Azure your job"

Dan 55

Azure is hardly cheap though. It's as if you buy a ticket from BA and get Ryanair levels of service (which sounds about right too).

MS makes you look like a fool for their mistakes

A random security guy

MS for years they have messed up and still gone laughing to the bank. They are still at it, I guess.

Anonymous Coward

Ernestine from Microsoft Support has responded: https://vimeo.com/355556831

Back to their old tricks

teebie

"Oh, did you get breached, well that's because you're using linux, if you bought a licence for our servers this would never have happened."

Re: Back to their old tricks

Mage

t makes more sense to run a VM with Windows (when you need windows) on LOCAL HW running Linux natively.

Windows and especially Azure is worst at Security.

1998 and MS lies about Linux.

Let's start with a fairly fundamental question here

Anonymous Coward

If you're at a minimum Linux aware, why on God's green Earth would you ever want to even go near a Microsoft product to run it on (those who have no choice due to company policy excepted, of course, I feel for you)?!?

That's like building a bank safe out of meringue.

Re: Let's start with a fairly fundamental question here

gerdesj

"That's like building a bank safe out of meringue."

My efforts at meringue makes the Scone of Stone look like candyfloss ...

H4xx

batfastad

Could M$ not just have added to their statement to ask the miscreants using/accessing all these VMs to update the agent on their way out once they are done? I mean that's not far away from the zero-fscks that M$ clearly give.

The uneasy feeling about all the MS provided (spy) stuff on their Linux Azure VM's

naive

unfortunately became true.

The good version is 1.6.8.1, OMI is not part of any major distro, so has to be upgraded by hand.

https://github.com/Microsoft/omi/releases/tag/v1.6.8-1

Check openssl version first, to determine if the 100 or 110 version of he package is required

Debian/Ubuntu: apt list --installed | grep -i ssl

RedHat/centOS: yum list installed | grep -i ssl

Debian:

Check currently installed OMI version

apt list --installed | grep -i omi

Depending on the openssl version, 1.00 or 1.10 a specific package of the new omi needs to be installed.

wget https://github.com/microsoft/omi/releases/download/v1.6.8-1/omi-1.6.8-1.ssl_110.ulinux.x64.deb

dpkg -i omi-1.6.8-1.ssl_110.ulinux.x64.deb

RedHat/CentOS:

Also check here if the 100 or the 110 version is required.

Check installed OMI version

yum list installed | grep -i omi

wget https://github.com/microsoft/omi/releases/download/v1.6.8-1/omi-1.6.8-1.ssl_110.ulinux.x64.rpm

rpm -Uvh omi-1.6.8-1.ssl_100.ulinux.x64.rpm

Under heaven all can see beauty as beauty only because there is ugliness.
All can know good as good only because there is evil.
Therefore having and not having arise together.
Difficult and easy complement each other.
Long and short contrast each other:
High and low rest upon each other;
Voice and sound harmonize each other;
Front and back follow one another.
Therefore the sage goes about doing nothing, teaching no-talking.
The ten thousand things rise and fall without cease,
Creating, yet not.
Working, yet not taking credit.
Work is done, then forgotten.
Therefore it lasts forever.