Web Hack List

Collected research

Exploiting Exchange PowerShell After ProxyNotShell: Part 1 - MultiValuedProperty

Zero Day Initiative — Exploiting Exchange PowerShell After ProxyNotShell: Part 1

After ProxyNotShell was patched with a type allow list governing Exchange PowerShell Remoting deserialization, this article shows the allow list itself contains an abusable generic: MultiValuedProperty<T>, whose single-argument constructor performs parse- and constructor-based conversion on an unvalidated type parameter, reaching XamlReader.Parse and remote code execution. A later bypass of the first patch reaches the same primitive through the allowed Command class.

Record

Document
Zero Day Initiative — Exploiting Exchange PowerShell After ProxyNotShell: Part 1
Researcher
Piotr Bazydło
Published by
Zero Day Initiative
Date
Format
Advisory
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Piotr Bazydło, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .