1.9 Ensure 'Extend Flash content setting to all content' is set to 'Disabled'

Information

Controls if all Flash content embedded on websites that have been set to allow Flash in content settings - either by the user or by enterprise policy - will be run, including content from other origins or small content.
Rationale:
Cross-domain Flash plugins or 'hidden' flash content may be malicious and therefore shall be prevented from being displayed.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled:
Computer Configuration\Administrative Templates\Google\Google Chrome\Extend Flash content setting to all content
Impact:
Flash content from other origins or small content might be blocked.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18, CSCv7|7.2

Plugin: Windows

Control ID: 99b9af1d37f711ac171059dc492da7fe7b00c0b7f8027dc13615690ed004ba39