diff --git a/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs b/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs index 39b7b0962f..02cad71a97 100644 --- a/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs +++ b/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs @@ -2,16 +2,18 @@ // Licensed under the MIT License. using System; -using System.Diagnostics; using System.Collections.Generic; using System.Collections.ObjectModel; +using System.Diagnostics; +using System.Diagnostics.CodeAnalysis; using System.Globalization; using System.Management.Automation; using System.Management.Automation.Host; using System.Management.Automation.Internal; -using System.Management.Automation.Runspaces; using System.Management.Automation.Remoting; -using System.Diagnostics.CodeAnalysis; +using System.Management.Automation.Runspaces; +using System.Management.Automation.Security; +using System.Text; namespace Microsoft.PowerShell.Commands { @@ -113,6 +115,19 @@ namespace Microsoft.PowerShell.Commands /// protected override void EndProcessing() { + // Check if system is in locked down mode, in which case this cmdlet is disabled. + if (SystemPolicy.GetSystemLockdownPolicy() == SystemEnforcementMode.Enforce) + { + WriteError( + new ErrorRecord( + new PSSecurityException(RemotingErrorIdStrings.EnterPSHostProcessCmdletDisabled), + "EnterPSHostProcessCmdletDisabled", + ErrorCategory.SecurityError, + null)); + + return; + } + // Check for host that supports interactive remote sessions. _interactiveHost = this.Host as IHostSupportsInteractiveSession; if (_interactiveHost == null) diff --git a/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx b/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx index bd712339b7..9ad52f6743 100644 --- a/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx +++ b/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx @@ -1667,4 +1667,7 @@ All WinRM sessions connected to PowerShell session configurations, such as Micro Information about the process could not be read: '{0}'. + + Enter-PSHostProcess cmdlet is disabled because an application control policy such as 'AppLocker' or 'Windows Defender Application Control' is in enforcement. + diff --git a/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 b/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 index a09e22492d..09293bd695 100644 --- a/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 +++ b/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 @@ -1164,6 +1164,31 @@ try } } + Describe "Enter-PSHostProcess cmdlet should be disabled on locked down systems" -Tags 'Feature','RequireAdminOnWindows' { + + It "Verifies that Enter-PSHostProcess is disabled with lock down policy" { + + $expectedError = $null + try + { + Invoke-LanguageModeTestingSupportCmdlet -SetLockdownMode + $ExecutionContext.SessionState.LanguageMode = "ConstrainedLanguage" + + Enter-PSHostProcess -Id 5555 -ErrorAction Stop + } + catch + { + $expectedError = $_ + } + finally + { + Invoke-LanguageModeTestingSupportCmdlet -RevertLockdownMode -EnableFullLanguageMode + } + + $expectedError.FullyQualifiedErrorId | Should -BeExactly 'EnterPSHostProcessCmdletDisabled,Microsoft.PowerShell.Commands.EnterPSHostProcessCommand' + } + } + # End Describe blocks } finally