Web Hack List

Other nomination

Exploiting Exchange PowerShell After ProxyNotShell: Part 1 - MultiValuedProperty

After ProxyNotShell was patched with a type allow list governing Exchange PowerShell Remoting deserialization, this article shows the allow list itself contains an abusable generic: MultiValuedProperty<T>, whose single-argument constructor performs parse- and constructor-based conversion on an unvalidated type parameter, reaching XamlReader.Parse and remote code execution. A later bypass of the first patch reaches the same primitive through the allowed Command class.

Record

Researcher
Piotr Bazydło
Published by
Zero Day Initiative
Date
Format
Advisory

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Piotr Bazydło, first published at the original source. Preserved copies are kept so the citation survives its host.