mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
Restrict loading of amsi.dll from system32 folder (#12730)
<!-- Anything that looks like this is a comment and can't be seen after the Pull Request is created. --> # PR Summary Restrict search path for `amsi.dll` and `wldp.dll` to just System32 on Windows ## PR Checklist - [x] [PR has a meaningful title](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - Use the present tense and imperative mood when describing your changes - [x] [Summarized changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [x] [Make sure all `.h`, `.cpp`, `.cs`, `.ps1` and `.psm1` files have the correct copyright header](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [x] This PR is ready to merge and is not [Work in Progress](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---work-in-progress). - If the PR is work in progress, please add the prefix `WIP:` or `[ WIP ]` to the beginning of the title (the `WIP` bot will keep its status check at `Pending` while the prefix is present) and remove the prefix when the PR is ready. - **[Breaking changes](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#making-breaking-changes)** - [x] None - **OR** - [ ] [Experimental feature(s) needed](https://github.com/MicrosoftDocs/PowerShell-Docs/blob/staging/reference/6/Microsoft.PowerShell.Core/About/about_Experimental_Features.md) - [ ] Experimental feature name(s): <!-- Experimental feature name(s) here --> - **User-facing changes** - [x] Not Applicable - **OR** - [ ] [Documentation needed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#pull-request---submission) - [ ] Issue filed: <!-- Number/link of that issue here --> - **Testing - New and feature** - [x] N/A or can only be tested interactively - **OR** - [ ] [Make sure you've added a new test if existing tests do not effectively test the code changed](https://github.com/PowerShell/PowerShell/blob/master/.github/CONTRIBUTING.md#before-submitting) - **Tooling** - [x] I have considered the user experience from a tooling perspective and don't believe tooling will be impacted. - **OR** - [ ] I have considered the user experience from a tooling perspective and enumerated concerns in the summary. This may include: - Impact on [PowerShell Editor Services](https://github.com/PowerShell/PowerShellEditorServices) which is used in the [PowerShell extension](https://github.com/PowerShell/vscode-powershell) for VSCode (which runs in a different PS Host). - Impact on Completions (both in the console and in editors) - one of PowerShell's most powerful features. - Impact on [PSScriptAnalyzer](https://github.com/PowerShell/PSScriptAnalyzer) (which provides linting & formatting in the editor extensions). - Impact on [EditorSyntax](https://github.com/PowerShell/EditorSyntax) (which provides syntax highlighting with in VSCode, GitHub, and many other editors).
This commit is contained in:
@@ -1751,24 +1751,28 @@ namespace System.Management.Automation
|
||||
/// Return Type: HRESULT->LONG->int
|
||||
///appName: LPCWSTR->WCHAR*
|
||||
///amsiContext: HAMSICONTEXT*
|
||||
[DefaultDllImportSearchPathsAttribute(DllImportSearchPath.System32)]
|
||||
[DllImportAttribute("amsi.dll", EntryPoint = "AmsiInitialize", CallingConvention = CallingConvention.StdCall)]
|
||||
internal static extern int AmsiInitialize(
|
||||
[InAttribute()] [MarshalAsAttribute(UnmanagedType.LPWStr)] string appName, ref System.IntPtr amsiContext);
|
||||
|
||||
/// Return Type: void
|
||||
///amsiContext: HAMSICONTEXT->HAMSICONTEXT__*
|
||||
[DefaultDllImportSearchPathsAttribute(DllImportSearchPath.System32)]
|
||||
[DllImportAttribute("amsi.dll", EntryPoint = "AmsiUninitialize", CallingConvention = CallingConvention.StdCall)]
|
||||
internal static extern void AmsiUninitialize(System.IntPtr amsiContext);
|
||||
|
||||
/// Return Type: HRESULT->LONG->int
|
||||
///amsiContext: HAMSICONTEXT->HAMSICONTEXT__*
|
||||
///amsiSession: HAMSISESSION*
|
||||
[DefaultDllImportSearchPathsAttribute(DllImportSearchPath.System32)]
|
||||
[DllImportAttribute("amsi.dll", EntryPoint = "AmsiOpenSession", CallingConvention = CallingConvention.StdCall)]
|
||||
internal static extern int AmsiOpenSession(System.IntPtr amsiContext, ref System.IntPtr amsiSession);
|
||||
|
||||
/// Return Type: void
|
||||
///amsiContext: HAMSICONTEXT->HAMSICONTEXT__*
|
||||
///amsiSession: HAMSISESSION->HAMSISESSION__*
|
||||
[DefaultDllImportSearchPathsAttribute(DllImportSearchPath.System32)]
|
||||
[DllImportAttribute("amsi.dll", EntryPoint = "AmsiCloseSession", CallingConvention = CallingConvention.StdCall)]
|
||||
internal static extern void AmsiCloseSession(System.IntPtr amsiContext, System.IntPtr amsiSession);
|
||||
|
||||
@@ -1779,6 +1783,7 @@ namespace System.Management.Automation
|
||||
///contentName: LPCWSTR->WCHAR*
|
||||
///amsiSession: HAMSISESSION->HAMSISESSION__*
|
||||
///result: AMSI_RESULT*
|
||||
[DefaultDllImportSearchPathsAttribute(DllImportSearchPath.System32)]
|
||||
[DllImportAttribute("amsi.dll", EntryPoint = "AmsiScanBuffer", CallingConvention = CallingConvention.StdCall)]
|
||||
internal static extern int AmsiScanBuffer(
|
||||
System.IntPtr amsiContext, System.IntPtr buffer, uint length,
|
||||
@@ -1790,6 +1795,7 @@ namespace System.Management.Automation
|
||||
///contentName: LPCWSTR->WCHAR*
|
||||
///amsiSession: HAMSISESSION->HAMSISESSION__*
|
||||
///result: AMSI_RESULT*
|
||||
[DefaultDllImportSearchPathsAttribute(DllImportSearchPath.System32)]
|
||||
[DllImportAttribute("amsi.dll", EntryPoint = "AmsiScanString", CallingConvention = CallingConvention.StdCall)]
|
||||
internal static extern int AmsiScanString(
|
||||
System.IntPtr amsiContext, [InAttribute()] [MarshalAsAttribute(UnmanagedType.LPWStr)] string @string,
|
||||
|
||||
@@ -564,6 +564,7 @@ namespace System.Management.Automation.Security
|
||||
/// pHostInformation: PWLDP_HOST_INFORMATION->_WLDP_HOST_INFORMATION*
|
||||
/// pdwLockdownState: PDWORD->DWORD*
|
||||
/// dwFlags: DWORD->unsigned int
|
||||
[DefaultDllImportSearchPathsAttribute(DllImportSearchPath.System32)]
|
||||
[DllImportAttribute("wldp.dll", EntryPoint = "WldpGetLockdownPolicy")]
|
||||
internal static extern int WldpGetLockdownPolicy(ref WLDP_HOST_INFORMATION pHostInformation, ref uint pdwLockdownState, uint dwFlags);
|
||||
|
||||
@@ -572,6 +573,7 @@ namespace System.Management.Automation.Security
|
||||
/// pHostInformation: PWLDP_HOST_INFORMATION->_WLDP_HOST_INFORMATION*
|
||||
/// ptIsApproved: PBOOL->BOOL*
|
||||
/// dwFlags: DWORD->unsigned int
|
||||
[DefaultDllImportSearchPathsAttribute(DllImportSearchPath.System32)]
|
||||
[DllImportAttribute("wldp.dll", EntryPoint = "WldpIsClassInApprovedList")]
|
||||
internal static extern int WldpIsClassInApprovedList(ref Guid rclsid, ref WLDP_HOST_INFORMATION pHostInformation, ref int ptIsApproved, uint dwFlags);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user