Exploiting Exchange PowerShell After ProxyNotShell: Part 1 - MultiValuedProperty
ID: e2dc0851-6656-588a-91d5-7cc4fc716e65
STIX ID: report--e2dc0851-6656-588a-91d5-7cc4fc716e65
Feed Name: Zero Day Initiative (ZDI) Blog
This research article analyzes two Exchange Server RCE issues: CVE-2023-21529 (abuse of an allowed MultiValuedProperty deserialization type) and CVE-2023-32031 (a bypass using the Command class). It describes how these enable post-auth remote code execution via Exchange PowerShell remoting, discusses Microsoft’s deserialization allow list and patches, and demonstrates exploitation primitives and patch bypass techniques that could let low-privileged internal users escalate to SYSTEM on Exchange servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
