logo

Exploiting Exchange PowerShell After ProxyNotShell: Part 1 - MultiValuedProperty

ID: e2dc0851-6656-588a-91d5-7cc4fc716e65

STIX ID: report--e2dc0851-6656-588a-91d5-7cc4fc716e65

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
75/100

Date Published: 2024-09-05

Date Updated: 2026-05-01

Author: Piotr Bazydło

...
...

This research article analyzes two Exchange Server RCE issues: CVE-2023-21529 (abuse of an allowed MultiValuedProperty deserialization type) and CVE-2023-32031 (a bypass using the Command class). It describes how these enable post-auth remote code execution via Exchange PowerShell remoting, discusses Microsoft’s deserialization allow list and patches, and demonstrates exploitation primitives and patch bypass techniques that could let low-privileged internal users escalate to SYSTEM on Exchange servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.