{"id":17610,"date":"2021-09-21T11:03:10","date_gmt":"2021-09-21T09:03:10","guid":{"rendered":"https:\/\/www.kaspersky.fr\/blog\/?p=17610"},"modified":"2021-09-21T11:03:10","modified_gmt":"2021-09-21T09:03:10","slug":"vulnerabilities-in-omi-azure","status":"publish","type":"post","link":"https:\/\/www.kaspersky.fr\/blog\/vulnerabilities-in-omi-azure\/17610\/","title":{"rendered":"Des vuln\u00e9rabilit\u00e9s dans OMI menacent les machines virtuelles Linux sur Microsoft Azure"},"content":{"rendered":"<p>Les m\u00e9dias <a href=\"https:\/\/www.wiz.io\/blog\/secret-agent-exposes-azure-customers-to-unauthorized-code-execution\" target=\"_blank\" rel=\"noopener nofollow\">se font l\u2019\u00e9cho<\/a> d\u2019une pratique assez dangereuse sur Microsoft Azure, plus pr\u00e9cis\u00e9ment lorsqu\u2019un utilisateur cr\u00e9e une machine virtuelle Linux et autorise certaines services Azure, puisque la plateforme Azure installe automatiquement l\u2019agent logiciel open-source <em>Open Management Infrastructure<\/em> (OMI) sur la machine. De plus, l\u2019utilisateur n\u2019en a pas connaissance.<\/p>\n<p>M\u00eame si l\u2019id\u00e9e d\u2019une installation secr\u00e8te peut sembler terrible \u00e0 premi\u00e8re vue, celle-ci n\u2019est pas si n\u00e9faste mis \u00e0 part pour deux raisons. Tout d\u2019abord, l\u2019agent est vuln\u00e9rable et on le sait. Ensuite, l\u2019agent ne dispose pas d\u2019un m\u00e9canisme de mise \u00e0 jour automatique sur Azure. En attendant que Microsoft r\u00e8gle le probl\u00e8me de son c\u00f4t\u00e9, les organisations qui utilisent les machines virtuelles Linux sur Azure vont devoir passer \u00e0 l\u2019action.<\/p>\n<h2>Les failles de l\u2019Open Management Infrastructure et leur exploitation<\/h2>\n<p>\u00c0 l\u2019occasion de son Patch Tuesday de septembre, Microsoft a publi\u00e9 des mises \u00e0 jour de s\u00e9curit\u00e9 pour corriger quatre vuln\u00e9rabilit\u00e9s dans l\u2019agent <em>Open Management Infrastructure<\/em>. Une d\u2019elles, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-38647\" target=\"_blank\" rel=\"noopener nofollow\">CVE-2021-38647<\/a>, permet <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/remote-code-execution-rce\/\" target=\"_blank\" rel=\"noopener\">l\u2019ex\u00e9cution de code \u00e0 distance<\/a> (RCE) et est critique. Les trois autres, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-38648\" target=\"_blank\" rel=\"noopener nofollow\">CVE-2021-38648<\/a>, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-38645\" target=\"_blank\" rel=\"noopener nofollow\">CVE-2021-38645<\/a> et <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-38649\" target=\"_blank\" rel=\"noopener nofollow\">CVE-2021-38649<\/a> peuvent \u00eatre utilis\u00e9es pour <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/privilege-escalation\/\" target=\"_blank\" rel=\"noopener\">\u00e9lever les privil\u00e8ges (LPE)<\/a> lors d\u2019attaques \u00e0 plusieurs \u00e9tapes et apr\u00e8s que les cybercriminels ont p\u00e9n\u00e9tr\u00e9 dans le r\u00e9seau de la victime. Ces trois vuln\u00e9rabilit\u00e9s ont un score CVSS \u00e9lev\u00e9.<\/p>\n<p>Lorsque les utilisateurs de Microsoft Azure cr\u00e9e une machine virtuelle Linux et autorise tout un ensemble de services, OMI (avec toutes ses failles) se d\u00e9ploie automatiquement dans le syst\u00e8me. Ces services incluent notamment <em>Azure Automation, Azure Automatic Update, Azure Operations Management Suite, Azure Log Analytics, Azure Configuration Management <\/em>et <em>Azure Diagnostics<\/em>. Une liste qui est loin d\u2019\u00eatre compl\u00e8te. L\u2019agent <em>Open Management Infrastructure<\/em> poss\u00e8de d\u00e9j\u00e0 les privil\u00e8ges les plus \u00e9lev\u00e9s dans le syst\u00e8me, et comme ses t\u00e2ches incluent notamment la collecte de statistiques et la synchronisation des param\u00e8tres de configuration, on peut g\u00e9n\u00e9ralement y acc\u00e9der via Internet gr\u00e2ce \u00e0 plusieurs ports HTTP, selon les services activ\u00e9s.<\/p>\n<p>Par exemple, si le port d\u2019\u00e9coute est 5986, les cybercriminels peuvent exploiter la vuln\u00e9rabilit\u00e9 CVE-2021-38647 et ex\u00e9cuter le code \u00e0 distance. Si l\u2019OMI peut \u00eatre g\u00e9r\u00e9 \u00e0 distance (via les ports 5986, 5985 ou 1270), toute personne externe peut exploiter cette m\u00eame faille pour acc\u00e9der \u00e0 tout le voisinage r\u00e9seau dans Azure. Les experts disent que cette faille est tr\u00e8s facilement exploitable.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">This is even more severe. The RCE is the simplest RCE you can ever imagine. Simply remove the auth header and you are root. remotely. on all machines. Is this really 2021? <a href=\"https:\/\/t.co\/iIHNyqgew4\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/iIHNyqgew4<\/a><\/p>\n<p>\u2014 Ami Luttwak (@amiluttwak) <a href=\"https:\/\/twitter.com\/amiluttwak\/status\/1437898746747097090?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">September 14, 2021<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Pour le moment, aucune attaque n\u2019a \u00e9t\u00e9 signal\u00e9e, mais avec toutes les informations disponibles et la facilit\u00e9 d\u2019exploitation de ces vuln\u00e9rabilit\u00e9s, il est fort probable que la situation change.<\/p>\n<h2>Comment vous prot\u00e9ger<\/h2>\n<p>Microsoft a publi\u00e9 les correctifs de ces quatre vuln\u00e9rabilit\u00e9s. Par contre, l\u2019OMI n\u2019installe pas automatiquement les mises \u00e0 jour donc vous devez v\u00e9rifier manuellement pour voir quelle version est d\u00e9ploy\u00e9e sur votre machine virtuelle Linux. Si elle est post\u00e9rieure \u00e0 1.6.8.1, mettez \u00e0 jour l\u2019agent <em>Open Management Infrastructure<\/em>. Pour savoir comment proc\u00e9der, consultez la description de la vuln\u00e9rabilit\u00e9 <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-38647\" target=\"_blank\" rel=\"noopener nofollow\">CVE-2021-38647<\/a>.<\/p>\n<p>Les experts recommandent \u00e9galement de restreindre l\u2019acc\u00e8s r\u00e9seau des ports 5985, 5986 et 1270 pour emp\u00eacher quiconque de lancer une attaque et d\u2019ex\u00e9cuter un code \u00e0 distance.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>L\u2019agent Open Management Infrastructure et ses quatre vuln\u00e9rabilit\u00e9s sont automatiquement install\u00e9s sur les machines virtuelles Linux avec Microsoft Azure.<\/p>\n","protected":false},"author":2581,"featured_media":17611,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2112,3150,3151],"tags":[4196,623,31,322],"class_list":{"0":"post-17610","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-enterprise","9":"category-smb","10":"tag-azure","11":"tag-linux","12":"tag-microsoft","13":"tag-vulnerabilites"},"hreflang":[{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/vulnerabilities-in-omi-azure\/17610\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/vulnerabilities-in-omi-azure\/23305\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/vulnerabilities-in-omi-azure\/18792\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/vulnerabilities-in-omi-azure\/25371\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/vulnerabilities-in-omi-azure\/23452\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/vulnerabilities-in-omi-azure\/22852\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/vulnerabilities-in-omi-azure\/25976\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/vulnerabilities-in-omi-azure\/25558\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/vulnerabilities-in-omi-azure\/31483\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/vulnerabilities-in-omi-azure\/10060\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/vulnerabilities-in-omi-azure\/41977\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/vulnerabilities-in-omi-azure\/18124\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/vulnerabilities-in-omi-azure\/15271\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/vulnerabilities-in-omi-azure\/27374\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/vulnerabilities-in-omi-azure\/31634\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/vulnerabilities-in-omi-azure\/27564\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/vulnerabilities-in-omi-azure\/24347\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/vulnerabilities-in-omi-azure\/29691\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/vulnerabilities-in-omi-azure\/29485\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.fr\/blog\/tag\/vulnerabilites\/","name":"Vuln\u00e9rabilit\u00e9s"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.fr\/blog\/wp-json\/wp\/v2\/posts\/17610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.fr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.fr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.fr\/blog\/wp-json\/wp\/v2\/users\/2581"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.fr\/blog\/wp-json\/wp\/v2\/comments?post=17610"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.fr\/blog\/wp-json\/wp\/v2\/posts\/17610\/revisions"}],"predecessor-version":[{"id":17613,"href":"https:\/\/www.kaspersky.fr\/blog\/wp-json\/wp\/v2\/posts\/17610\/revisions\/17613"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.fr\/blog\/wp-json\/wp\/v2\/media\/17611"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.fr\/blog\/wp-json\/wp\/v2\/media?parent=17610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.fr\/blog\/wp-json\/wp\/v2\/categories?post=17610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.fr\/blog\/wp-json\/wp\/v2\/tags?post=17610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}