logo

Exploiting Exchange PowerShell After ProxyNotShell: Part 2 - ApprovedApplicationCollection

ID: 6c1af3f4-afe2-5ac0-9f7e-4928e70005bb

STIX ID: report--6c1af3f4-afe2-5ac0-9f7e-4928e70005bb

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
75/100

Date Published: 2024-09-12

Date Updated: 2026-05-01

Author: Piotr Bazydło

...
...

This report details a demonstrated RCE chain against Microsoft Exchange that combines an Exchange deserialization issue (CVE-2023-36756) with an unpatched path traversal in the Windows utility extrac32.exe (ZDI-CAN-21499). It explains how allow/deny list shortcomings in PowerShell remoting deserialization (MultiValuedProperty) permitted abuse of classes such as ApprovedApplicationCollection, recounts prior related CVEs and patches (including CVE-2023-32031), and notes Microsoft chose not to patch the extrac32 issue despite the demonstrated impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.