logo

Exploiting Exchange PowerShell After ProxyNotShell: Part 4 – No Argument Constructor

ID: fd5aa18e-69a9-5caa-86a2-7b88021a6510

STIX ID: report--fd5aa18e-69a9-5caa-86a2-7b88021a6510

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
60/100

Date Published: 2024-09-26

Date Updated: 2026-05-01

Author: Piotr Bazydło

...
...

This excerpt from an Exchange PowerShell research series analyzes the ConvertViaNoArgumentConstructor deserialization mechanism, explains how a recent patch changed type validation to an allow list (affecting previous RCE chains), and highlights that no-argument-constructor-based conversions remain a powerful vector for building remote code execution chains despite the mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.