Exploiting Exchange PowerShell After ProxyNotShell: Part 4 – No Argument Constructor
ID: fd5aa18e-69a9-5caa-86a2-7b88021a6510
STIX ID: report--fd5aa18e-69a9-5caa-86a2-7b88021a6510
Feed Name: Zero Day Initiative (ZDI) Blog
Threat Score
This excerpt from an Exchange PowerShell research series analyzes the ConvertViaNoArgumentConstructor deserialization mechanism, explains how a recent patch changed type validation to an allow list (affecting previous RCE chains), and highlights that no-argument-constructor-based conversions remain a powerful vector for building remote code execution chains despite the mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
