Information
This policy setting determines whether a page can control embedded WebBrowser controls
via script. If you enable this policy setting, script access to the WebBrowser control is
allowed. If you disable this policy setting, script access to the WebBrowser control is not
allowed. If you do not configure this policy setting, the user can enable or disable script
access to the WebBrowser control. By default, script access to the WebBrowser control is
allowed only in the Local Machine and Intranet zones. The recommended state for this
setting is- Enabled-Disable.
*Rationale*
A website hosted by a malicious person could attempt to exploit this feature. For example,
in the past there have been cross-site scripting vulnerabilities that were exploited to use
various WebBrowser controls.
Solution
To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.
Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow scripting of
Internet Explorer WebBrowser controlsThen set the Internet Explorer web browser control option to Disable.