Collected research
Exploiting Exchange PowerShell After ProxyNotShell: Part 1 - MultiValuedProperty
Zero Day Initiative — Exploiting Exchange PowerShell After ProxyNotShell: Part 1
After ProxyNotShell was patched with a type allow list governing Exchange PowerShell Remoting deserialization, this article shows the allow list itself contains an abusable generic: MultiValuedProperty<T>, whose single-argument constructor performs parse- and constructor-based conversion on an unvalidated type parameter, reaching XamlReader.Parse and remote code execution. A later bypass of the first patch reaches the same primitive through the allowed Command class.
Record
- Document
- Zero Day Initiative — Exploiting Exchange PowerShell After ProxyNotShell: Part 1
- Researcher
- Piotr Bazydło
- Published by
- Zero Day Initiative
- Date
- Format
- Advisory
- Topic
- HTTP
In the archive
Related sources
- Half Measures and Full Compromise: Exploiting Microsoft Exchange PowerShell Remoting
- blog post Advisory
Tags
This page is the archive's own catalogue record. The research is the work of Piotr Bazydło, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .