logo

PowerShell, C-Sharp and DDE The Power Within

ID: 4cfbff62-aaaf-5b04-b30e-42173a1b7e34

STIX ID: report--4cfbff62-aaaf-5b04-b30e-42173a1b7e34

Feed Name: SensePost Blog

Threat Score
60/100

Date Published: 2016-05-20

Date Updated: 2026-04-29

...
...

**Executive summary:** This blog post demonstrates how to combine a PowerShell exploit for MS16-032 (using embedded C# and DllImport calls) with Microsoft Excel DDE command execution to remotely load and run code and obtain a SYSTEM reverse shell; it provides code snippets, DDE formulas, and details on adding Winsock functions and STARTUPINFO handle redirection to spawn a socket-backed CMD process.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.