-
Notifications
You must be signed in to change notification settings - Fork 7.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Disallow Add-Type
in NoLanguage
mode on a locked down machine
#16245
Conversation
Normally, the Add-Type cmdlet is disallowed when PowerShell is run on a locked down system. However, an admin on a locked down system can create a NoLanguage remoting endpoint, and that endpoint configuration will allow the Add-Type cmdlet. The admin can create a remote connection to the NoLanguage endpoint on the same machine, and use Add-Type cmdlet to compile and run arbitrary C# code. This fix disallows the use of Add-Type cmdlet in a NoLanguage mode PowerShell session, on a locked down machine. Cherry picked from !17521
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please change the title to the following. It's used for 7.0.8 and 7.1.5.
Disallow
Add-Type
in NoLanguage mode on a locked down machine
Add-Type
in NoLanguage
mode on a locked down machine
🎉 Handy links: |
🎉 Handy links: |
PR Summary
Normally, the Add-Type cmdlet is disallowed when PowerShell is run on a locked down system. However, an admin on a locked down system can create a NoLanguage remoting endpoint, and that endpoint configuration will allow the Add-Type cmdlet. The admin can create a remote connection to the NoLanguage endpoint on the same machine, and use Add-Type cmdlet to compile and run arbitrary C# code.
This fix disallows the use of Add-Type cmdlet in a NoLanguage mode PowerShell session, on a locked down machine.
PR Context
PR Checklist
.h
,.cpp
,.cs
,.ps1
and.psm1
files have the correct copyright headerWIP:
or[ WIP ]
to the beginning of the title (theWIP
bot will keep its status check atPending
while the prefix is present) and remove the prefix when the PR is ready.(which runs in a different PS Host).