PowerShell Constrained Language Mode: Unclear handling of dynamic .NET object properties
0 reputation · 05 Jun 2025, 09:26 UTC
Goal
Enable scripts to access runtime‑generated properties on .NET objects while operating in Constrained Language Mode (CLM).
Constraints
- CLM blocks any property or method not explicitly on the allowed list.
- Dynamic properties created by COM objects or API wrappers are not present at compile time.
- AppLocker LanguageSessionMode may override or extend the allow‑list.
Uncertainty
When a script attempts to read a property that is generated at runtime on a restricted object, the current CLM implementation raises a generic security error without specifying whether the failure is due to the property itself, the object type, or the AppLocker policy. This ambiguity hampers troubleshooting and limits the ability of administrators to fine‑tune permissions.
Questions
- Does CLM provide a granular allow‑list that can include dynamic property names, or is the list static per object type?
- What is the expected behavior when a script accesses a runtime‑generated property on an object that is otherwise allowed under CLM?
- How does AppLocker’s LanguageSessionMode interact with CLM regarding the resolution of dynamic properties, and can it be configured to permit them selectively?