Back to directory
WRITEUP #3500

From Pwn2Own 2021: A New Attack Surface On Microsoft Exchange - Proxyshell!

RCEPrivilege escalation
by@orange_8361(Orange Tsai)
Bounty
200,000
Program
Microsoft
Published
Aug 18, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell
RELATED WRITEUPS
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
RCEDependency confusion
Attacking PowerShell CLIXML Deserialization
DeserializationInsecure deserialization
Escalating From Reader To Contributor In Azure API Management
Privilege Escalation
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS
RCEArbitrary file write

Built with ❤️ by Shubham Rawat