Collected research
Half Measures and Full Compromise: Exploiting Microsoft Exchange PowerShell Remoting
An index page for the author's Exchange PowerShell Remoting research, linking the OffensiveCon 2024 talk and slides and four Zero Day Initiative posts. It states the result: after ProxyNotShell, cmdlet arguments remain reachable through MultiValuedProperty, ApprovedApplicationCollection and no-argument constructors, and three gadgets - arbitrary file write, arbitrary file read and local DLL loading - chain into remote code execution on Exchange.
Record
- Researcher
- Piotr Bazydło
- Published by
- Piotr Bazydło (chudy)
- Topic
- Other
In the archive
Related sources
- Zero Day Initiative — Exploiting Exchange PowerShell After ProxyNotShell: Part 1 Advisory
- Technical article: part 2 Advisory
- Technical article: part 3 Advisory
- Technical article: part 4 Advisory
- OffensiveCon 2024 slides Whitepaper
- OffensiveCon24 - Piotr Bazydlo - Half Measures and Full Compromise
Tags
This page is the archive's own catalogue record. The research is the work of Piotr Bazydło, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .