Web Hack List

Collected research

Half Measures and Full Compromise: Exploiting Microsoft Exchange PowerShell Remoting

An index page for the author's Exchange PowerShell Remoting research, linking the OffensiveCon 2024 talk and slides and four Zero Day Initiative posts. It states the result: after ProxyNotShell, cmdlet arguments remain reachable through MultiValuedProperty, ApprovedApplicationCollection and no-argument constructors, and three gadgets - arbitrary file write, arbitrary file read and local DLL loading - chain into remote code execution on Exchange.

Record

Researcher
Piotr Bazydło
Published by
Piotr Bazydło (chudy)
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Piotr Bazydło, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .