Exploiting Exchange PowerShell After ProxyNotShell: Part 2 - ApprovedApplicationCollection
ID: 6c1af3f4-afe2-5ac0-9f7e-4928e70005bb
STIX ID: report--6c1af3f4-afe2-5ac0-9f7e-4928e70005bb
Feed Name: Zero Day Initiative (ZDI) Blog
This report details a demonstrated RCE chain against Microsoft Exchange that combines an Exchange deserialization issue (CVE-2023-36756) with an unpatched path traversal in the Windows utility extrac32.exe (ZDI-CAN-21499). It explains how allow/deny list shortcomings in PowerShell remoting deserialization (MultiValuedProperty) permitted abuse of classes such as ApprovedApplicationCollection, recounts prior related CVEs and patches (including CVE-2023-32031), and notes Microsoft chose not to patch the extrac32 issue despite the demonstrated impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
