9.3 Set 'Prevent downloading of enclosures' to 'Enabled'

Information



This policy setting prevents the user from having enclosures (file attachments)
downloaded from a feed to the user's computer.
If you enable this policy setting, the user cannot set the Feed Sync Engine to download an
enclosure through the Feed property page. A developer cannot change the download
setting through the Feed APIs.
If you disable or do not configure this policy setting, the user can set the Feed Sync Engine
to download an enclosure through the Feed property page. A developer can change the
download setting through the Feed APIs. The recommended state for this setting is-
Enabled.

*Rationale*

Enclosures could contain malicious payloads.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\RSS Feeds\Prevent
downloading of enclosures

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(3), CSCv6|13

Plugin: Windows

Control ID: 7a465989abd18a7ad77185d128a4edc470dd3a9a5f9bbb5abf06b921d05b4ced