From 121578f17df80e2fe8df4ddca44d0e508b5397e7 Mon Sep 17 00:00:00 2001 From: Paul Higinbotham Date: Mon, 8 Jul 2019 18:10:14 +0000 Subject: [PATCH] Merged PR 8968: Disable Enter-PSHostProcess cmdlet when system in lock down mode Enter-PSHostProcess on a locked down (WDAC enforced) machine allows any admin to connect to any another local hosted PowerShell process and execute commands as that user. This amounts to privilege escalation on the policy locked down machine and something we want to prevent. Fix is to check for system lock down and disable Enter-PSHostProcess cmdlet with an error message. --- .../commands/EnterPSHostProcessCommand.cs | 21 +++++++++++++--- .../resources/RemotingErrorIdStrings.resx | 3 +++ .../ConstrainedLanguageRestriction.Tests.ps1 | 25 +++++++++++++++++++ 3 files changed, 46 insertions(+), 3 deletions(-) diff --git a/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs b/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs index 39b7b0962f..02cad71a97 100644 --- a/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs +++ b/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs @@ -2,16 +2,18 @@ // Licensed under the MIT License. using System; -using System.Diagnostics; using System.Collections.Generic; using System.Collections.ObjectModel; +using System.Diagnostics; +using System.Diagnostics.CodeAnalysis; using System.Globalization; using System.Management.Automation; using System.Management.Automation.Host; using System.Management.Automation.Internal; -using System.Management.Automation.Runspaces; using System.Management.Automation.Remoting; -using System.Diagnostics.CodeAnalysis; +using System.Management.Automation.Runspaces; +using System.Management.Automation.Security; +using System.Text; namespace Microsoft.PowerShell.Commands { @@ -113,6 +115,19 @@ namespace Microsoft.PowerShell.Commands /// protected override void EndProcessing() { + // Check if system is in locked down mode, in which case this cmdlet is disabled. + if (SystemPolicy.GetSystemLockdownPolicy() == SystemEnforcementMode.Enforce) + { + WriteError( + new ErrorRecord( + new PSSecurityException(RemotingErrorIdStrings.EnterPSHostProcessCmdletDisabled), + "EnterPSHostProcessCmdletDisabled", + ErrorCategory.SecurityError, + null)); + + return; + } + // Check for host that supports interactive remote sessions. _interactiveHost = this.Host as IHostSupportsInteractiveSession; if (_interactiveHost == null) diff --git a/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx b/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx index bd712339b7..9ad52f6743 100644 --- a/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx +++ b/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx @@ -1667,4 +1667,7 @@ All WinRM sessions connected to PowerShell session configurations, such as Micro Information about the process could not be read: '{0}'. + + Enter-PSHostProcess cmdlet is disabled because an application control policy such as 'AppLocker' or 'Windows Defender Application Control' is in enforcement. + diff --git a/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 b/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 index a09e22492d..09293bd695 100644 --- a/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 +++ b/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 @@ -1164,6 +1164,31 @@ try } } + Describe "Enter-PSHostProcess cmdlet should be disabled on locked down systems" -Tags 'Feature','RequireAdminOnWindows' { + + It "Verifies that Enter-PSHostProcess is disabled with lock down policy" { + + $expectedError = $null + try + { + Invoke-LanguageModeTestingSupportCmdlet -SetLockdownMode + $ExecutionContext.SessionState.LanguageMode = "ConstrainedLanguage" + + Enter-PSHostProcess -Id 5555 -ErrorAction Stop + } + catch + { + $expectedError = $_ + } + finally + { + Invoke-LanguageModeTestingSupportCmdlet -RevertLockdownMode -EnableFullLanguageMode + } + + $expectedError.FullyQualifiedErrorId | Should -BeExactly 'EnterPSHostProcessCmdletDisabled,Microsoft.PowerShell.Commands.EnterPSHostProcessCommand' + } + } + # End Describe blocks } finally