Piotr Bazydło (chudy)

View on GitHub

Half Measures and Full Compromise: Exploiting Microsoft Exchange PowerShell Remoting

Collection of all materials concerning my Exchange PowerShell Remoting research. It includes OffensiveCon 2024 video and 4 blog posts, which include all the technical details.

Chain of 3 gadgets (Arbitrary File Write + Arbitrary File Read + Local DLL Loading) to achieve the RCE on Exchange is fully described in the 3rd blog post.