1.1.3 Ensure 'Allow remote users to interact with elevated windows in remote assistance sessions' is set to 'Disabled'.

Information

Google Chrome offers to run the remote assistance host in a process with uiAccess permissions. This allows remote users to interact with elevated windows on the local user's desktop.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled.


Computer Configuration\Administrative Templates\Google\Google Chrome\Configure remote access options\Allow remote users to interact with elevated windows in remote assistance sessions


Impact:
If this setting is disabled, the remote assistance host will run in the user's context. Furthermore, remote users cannot interact with elevated windows on the desktop.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv7|4

Plugin: Windows

Control ID: cf0f61a7d325bca690f2f2281bfa420ff9926d8bad1a8c8ea7aceef55cdda459