From 7dfcff92875d04d7756eec3e8fe310f3d377b800 Mon Sep 17 00:00:00 2001 From: Aditya Patwardhan Date: Tue, 16 Jul 2019 00:49:24 +0000 Subject: [PATCH] Merged PR 9168: Disable Enter-PSHostProcess cmdlet when system in lock down mode This is based on an issue, where Enter-PSHostProcess on a locked down (WDAC enforced) machine allows any admin to connect to any another local hosted PowerShell process and execute commands as that user. This amounts to privilege escalation on the policy locked down machine and something we want to prevent. Fix is to check for system lock down and disable Enter-PSHostProcess cmdlet with an error message. --- .../commands/EnterPSHostProcessCommand.cs | 14 +++++++++++ .../resources/RemotingErrorIdStrings.resx | 3 +++ .../ConstrainedLanguageRestriction.Tests.ps1 | 25 +++++++++++++++++++ 3 files changed, 42 insertions(+) diff --git a/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs b/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs index ab9ca5d1a4..129d7e6e2c 100644 --- a/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs +++ b/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs @@ -13,6 +13,7 @@ using System.Management.Automation.Host; using System.Management.Automation.Internal; using System.Management.Automation.Remoting; using System.Management.Automation.Runspaces; +using System.Management.Automation.Security; using System.Text; namespace Microsoft.PowerShell.Commands @@ -126,6 +127,19 @@ namespace Microsoft.PowerShell.Commands /// protected override void EndProcessing() { + // Check if system is in locked down mode, in which case this cmdlet is disabled. + if (SystemPolicy.GetSystemLockdownPolicy() == SystemEnforcementMode.Enforce) + { + WriteError( + new ErrorRecord( + new PSSecurityException(RemotingErrorIdStrings.EnterPSHostProcessCmdletDisabled), + "EnterPSHostProcessCmdletDisabled", + ErrorCategory.SecurityError, + null)); + + return; + } + // Check for host that supports interactive remote sessions. _interactiveHost = this.Host as IHostSupportsInteractiveSession; if (_interactiveHost == null) diff --git a/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx b/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx index 79cf08cdcd..d1bb929015 100644 --- a/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx +++ b/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx @@ -1684,4 +1684,7 @@ All WinRM sessions connected to PowerShell session configurations, such as Micro PowerShell remoting has been enabled only for PowerShell 6+ configurations and does not affect Windows PowerShell remoting configurations. Run this cmdlet in Windows PowerShell to affect all PowerShell remoting configurations. + + Enter-PSHostProcess cmdlet is disabled because an application control policy such as 'AppLocker' or 'Windows Defender Application Control' is in enforcement. + diff --git a/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 b/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 index 0c85c67a03..19ef2df2ce 100644 --- a/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 +++ b/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 @@ -1164,6 +1164,31 @@ try } } + Describe "Enter-PSHostProcess cmdlet should be disabled on locked down systems" -Tags 'Feature','RequireAdminOnWindows' { + + It "Verifies that Enter-PSHostProcess is disabled with lock down policy" { + + $expectedError = $null + try + { + Invoke-LanguageModeTestingSupportCmdlet -SetLockdownMode + $ExecutionContext.SessionState.LanguageMode = "ConstrainedLanguage" + + Enter-PSHostProcess -Id 5555 -ErrorAction Stop + } + catch + { + $expectedError = $_ + } + finally + { + Invoke-LanguageModeTestingSupportCmdlet -RevertLockdownMode -EnableFullLanguageMode + } + + $expectedError.FullyQualifiedErrorId | Should -BeExactly 'EnterPSHostProcessCmdletDisabled,Microsoft.PowerShell.Commands.EnterPSHostProcessCommand' + } + } + # End Describe blocks } finally