From bfbdc6c476f867b7a89b3478b5542423645c5475 Mon Sep 17 00:00:00 2001 From: Shirofune-Security <43838376+Shirofune-Security@users.noreply.github.com> Date: Mon, 21 Sep 2026 22:29:03 +0900 Subject: [PATCH] Read the owned release pipe with encoding-preamble detection --- scripts/AppLockerScriptWorker.ps1 | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/scripts/AppLockerScriptWorker.ps1 b/scripts/AppLockerScriptWorker.ps1 index 2ebb46fe..4f7be74b 100644 --- a/scripts/AppLockerScriptWorker.ps1 +++ b/scripts/AppLockerScriptWorker.ps1 @@ -1,7 +1,10 @@ # Fixed locally generated script; no external inputs or configuration writes. $ErrorActionPreference = 'Stop' [Console]::Out.WriteLine(('WELA_SCRIPT_READY___WELA_SCRIPT_NONCE__|' + $ExecutionContext.SessionState.LanguageMode + '|' + $PSVersionTable.PSVersion)) -$release = [Console]::In.ReadLine() +# .NET Framework's redirected-input writer may emit an encoding preamble. +# Read the owned pipe through a BOM-aware reader, without changing console state. +$pipeReader = [IO.StreamReader]::new([Console]::OpenStandardInput(), [Text.UTF8Encoding]::new($false, $true), $true, 128, $true) +try { $release = $pipeReader.ReadLine() } finally { $pipeReader.Dispose() } if ($release -cne 'WELA_SCRIPT_GO___WELA_SCRIPT_NONCE__') { exit 17 } [Console]::Out.WriteLine('WELA_SCRIPT_COMPLETE___WELA_SCRIPT_NONCE__') exit 0