From 8aee77cfeadfeb9e902bfd0b37e56047fe4356b9 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Tue, 22 Sep 2026 14:46:25 +0900 Subject: [PATCH] Bound unrelated command-line policy inventory --- scripts/ProcessCommandline.ps1 | 2 ++ 1 file changed, 2 insertions(+) diff --git a/scripts/ProcessCommandline.ps1 b/scripts/ProcessCommandline.ps1 index 1c61f6bf..315f740f 100644 --- a/scripts/ProcessCommandline.ps1 +++ b/scripts/ProcessCommandline.ps1 @@ -19,10 +19,12 @@ function Get-WelaProcessCommandlineSnapshot { $key=$parent.OpenSubKey('Audit') $unselected=[pscustomobject][ordered]@{Values=@();Children=@()} if ($key) { + if ($key.ValueCount -gt 128 -or $key.SubKeyCount -gt 128) {throw 'Unrelated policy inventory exceeds its 128-entry bound.'} $unselected.Values=@($key.GetValueNames()|Sort-Object|Where-Object {$_ -ine 'ProcessCreationIncludeCmdLine_Enabled'}|ForEach-Object { [pscustomobject][ordered]@{Name=$_;Type=$key.GetValueKind($_).ToString();Value=$key.GetValue($_,$null,[Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames)} }) $unselected.Children=@($key.GetSubKeyNames()|Sort-Object) + if (($unselected|ConvertTo-Json -Depth 12 -Compress).Length -gt 1048576) {throw 'Unrelated policy inventory exceeds its one Mi character bound.'} } } finally {if($key){$key.Dispose()};if($parent){$parent.Dispose()};$base.Dispose()} [pscustomobject][ordered]@{