logo

Exploiting Exchange PowerShell After ProxyNotShell: Part 3 – DLL Loading Chain for RCE

ID: 7a457731-1825-59c6-8d8c-51df97edc1b7

STIX ID: report--7a457731-1825-59c6-8d8c-51df97edc1b7

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
55/100

Date Published: 2024-09-19

Date Updated: 2026-05-01

Author: Piotr Bazydło

...
...

This report analyzes a local exploitation technique where the 'expand' utility is vulnerable to argument injection, allowing an attacker to bypass file-extension and path restrictions in a DumpDataReader workflow to extract and place a malicious DLL (FUSE.Paxos.dll). The write-primitive limitations are enumerated and then shown to be overcome by injecting flags (such as -i or -r) that nullify the -F filter, enabling arbitrary file extraction and facilitating DLL-based code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.