8.5.2 Set 'Initialize and script ActiveX controls not marked as safe' to 'Enabled:Disable'

Information



This policy setting allows you to manage ActiveX controls not marked as safe.
If you enable this policy setting, ActiveX controls are run, loaded with parameters, and
scripted without setting object safety for untrusted data or scripts. This setting is not
recommended, except for secure and administered zones. This setting causes both unsafe
and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked
safe for scripting option.
If you enable this policy setting and select Prompt in the drop-down box, users are queried
whether to allow the control to be loaded with parameters or scripted.
If you disable this policy setting, ActiveX controls that cannot be made safe are not loaded
with parameters or scripted.
If you do not configure this policy setting, users are queried whether to allow the control to
be loaded with parameters or scripted. The recommended state for this setting is-
Enabled-Disable.

*Rationale*

This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the
Script ActiveX controls marked safe for scripting option. This increases the risk of
malicious code being loaded and executed by the browser.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.


Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Initialize and script
ActiveX controls not marked as safeThen set the Initialize and script ActiveX controls not marked as safe option to
Disable.

Default Value-Prompt

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: e88a159bea44961f9abff03e1acf62d090972020b2417bc39210b0a6e02dddff