One Day Sec

What is the main advantage of the remote Exchange PowerShell access technique described in the article?

The technique allows executing Exchange PowerShell commands without requiring a domain-joined host or FQDN, expanding attack surface beyond conventional methods. It leverages NTLM authentication and bypasses restrictions fixed in CVE-2022–41040. This approach is particularly useful for post-ProxyShell scenarios where SSRF is patched but NTLM-enabled remote PowerShell remains accessible.
Exchange PowerShelldomain-joined hostNTLM authenticationCVE-2022-41040ProxyShell

Browse all Q&A →