Fix for partial PowerShell module search paths, that can be resolved to CWD locations - #17231
Merged
Merged
Conversation
… can be resolved to CWD locations The problem is .NET will return empty strings for special folders that don't exist in some accounts (like System account), and the module path code appends path locations without first checking if the root path is non-empty. This results in partial paths in the PSModulePath list, which are then interpreted by .NET file APIs as rooted in the current working directory. And this in turn can allow low privilege users to drop modules in locations that higher privilege accounts will load from, thus gaining escalated privilege code execution. These changes detect this non-rooted condition and prevents partial paths from being included in search lists. Cherry picked from !17201
Andrew (anmenaga)
requested review from
Steve Lee (SteveL-MSFT),
Travis Plunk (TravisEz13) and
Dongbo Wang (daxian-dbw)
April 29, 2022 18:23
|
This PR has Quantification details
Why proper sizing of changes matters
Optimal pull request sizes drive a better predictable PR flow as they strike a
What can I do to optimize my changes
How to interpret the change counts in git diff output
Was this comment helpful? 👍 :ok_hand: :thumbsdown: (Email) |
Travis Plunk (TravisEz13)
approved these changes
Apr 29, 2022
|
🎉 Handy links: |
Thatgfsj (Thatgfsj)
pushed a commit
to Thatgfsj/PowerShell
that referenced
this pull request
Aug 6, 2026
… can be resolved to CWD locations (PowerShell#17231) The problem is .NET will return empty strings for special folders that don't exist in some accounts (like System account), and the module path code appends path locations without first checking if the root path is non-empty. This results in partial paths in the PSModulePath list, which are then interpreted by .NET file APIs as rooted in the current working directory. And this in turn can allow low privilege users to drop modules in locations that higher privilege accounts will load from, thus gaining escalated privilege code execution. These changes detect this non-rooted condition and prevents partial paths from being included in search lists. Cherry picked from !17201 Co-authored-by: Travis Plunk <tplunk@microsoft.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR Summary
Cherry picked from release branch.
PR Checklist
.h,.cpp,.cs,.ps1and.psm1files have the correct copyright headerWIP:or[ WIP ]to the beginning of the title (theWIPbot will keep its status check atPendingwhile the prefix is present) and remove the prefix when the PR is ready.(which runs in a different PS Host).