Merged PR 8968: Disable Enter-PSHostProcess cmdlet when system in lock down mode

Enter-PSHostProcess on a locked down (WDAC enforced) machine allows any admin to connect to any another local hosted PowerShell process and execute commands as that user.  This amounts to privilege escalation on the policy locked down machine and something we want to prevent.

Fix is to check for system lock down and disable Enter-PSHostProcess cmdlet with an error message.
This commit is contained in:
Paul Higinbotham
2019-07-08 18:10:14 +00:00
committed by Travis Plunk
parent 9235f9babd
commit 121578f17d
3 changed files with 46 additions and 3 deletions
@@ -2,16 +2,18 @@
// Licensed under the MIT License.
using System;
using System.Diagnostics;
using System.Collections.Generic;
using System.Collections.ObjectModel;
using System.Diagnostics;
using System.Diagnostics.CodeAnalysis;
using System.Globalization;
using System.Management.Automation;
using System.Management.Automation.Host;
using System.Management.Automation.Internal;
using System.Management.Automation.Runspaces;
using System.Management.Automation.Remoting;
using System.Diagnostics.CodeAnalysis;
using System.Management.Automation.Runspaces;
using System.Management.Automation.Security;
using System.Text;
namespace Microsoft.PowerShell.Commands
{
@@ -113,6 +115,19 @@ namespace Microsoft.PowerShell.Commands
/// </summary>
protected override void EndProcessing()
{
// Check if system is in locked down mode, in which case this cmdlet is disabled.
if (SystemPolicy.GetSystemLockdownPolicy() == SystemEnforcementMode.Enforce)
{
WriteError(
new ErrorRecord(
new PSSecurityException(RemotingErrorIdStrings.EnterPSHostProcessCmdletDisabled),
"EnterPSHostProcessCmdletDisabled",
ErrorCategory.SecurityError,
null));
return;
}
// Check for host that supports interactive remote sessions.
_interactiveHost = this.Host as IHostSupportsInteractiveSession;
if (_interactiveHost == null)
@@ -1667,4 +1667,7 @@ All WinRM sessions connected to PowerShell session configurations, such as Micro
<data name="ProcessInfoNotRecoverable" xml:space="preserve">
<value>Information about the process could not be read: '{0}'.</value>
</data>
<data name="EnterPSHostProcessCmdletDisabled" xml:space="preserve">
<value>Enter-PSHostProcess cmdlet is disabled because an application control policy such as 'AppLocker' or 'Windows Defender Application Control' is in enforcement.</value>
</data>
</root>
@@ -1164,6 +1164,31 @@ try
}
}
Describe "Enter-PSHostProcess cmdlet should be disabled on locked down systems" -Tags 'Feature','RequireAdminOnWindows' {
It "Verifies that Enter-PSHostProcess is disabled with lock down policy" {
$expectedError = $null
try
{
Invoke-LanguageModeTestingSupportCmdlet -SetLockdownMode
$ExecutionContext.SessionState.LanguageMode = "ConstrainedLanguage"
Enter-PSHostProcess -Id 5555 -ErrorAction Stop
}
catch
{
$expectedError = $_
}
finally
{
Invoke-LanguageModeTestingSupportCmdlet -RevertLockdownMode -EnableFullLanguageMode
}
$expectedError.FullyQualifiedErrorId | Should -BeExactly 'EnterPSHostProcessCmdletDisabled,Microsoft.PowerShell.Commands.EnterPSHostProcessCommand'
}
}
# End Describe blocks
}
finally