Zero Day Initiative - Exploiting Exchange PowerShell After ProxyNotShell: Part 2 - ApprovedApplicationCollection

The ApprovedApplicationCollection gadget remains unlisted and accessible through MultiValuedProperty, exposing it to potential exploitation in Microsoft Exchange.
Despite identifying the path traversal in extrac32.exe that completes the RCE chain, Microsoft decided not to address the vulnerability citing a lack of customer exposure.
Read at Zero Day Initiative