8.1.11 Set 'Internet Explorer web browser control' to 'Enabled:Disable'

Information



This policy setting determines whether a page can control embedded WebBrowser controls
via script. If you enable this policy setting, script access to the WebBrowser control is
allowed. If you disable this policy setting, script access to the WebBrowser control is not
allowed.
If you do not configure this policy setting, the user can enable or disable script access to the
WebBrowser control. By default, script access to the WebBrowser control is allowed only in
the Local Machine and Intranet zones. The recommended state for this setting is-
Enabled-Disable.

*Rationale*

A website hosted by a malicious person could attempt to exploit this feature. For example,
in the past there have been cross-site scripting vulnerabilities that were exploited to use
various WebBrowser controls.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Internet Zone\Allow scripting of
Internet Explorer WebBrowser controlsThen set the Internet Explorer web browser control option to Disable.

Impact-If you enable this policy setting, script access to the WebBrowser control is allowed. If you
disable this policy setting, script access to the WebBrowser control is not allowed. If you do
not configure this policy setting, the user can enable or disable script access to the
WebBrowser control. By default, script access to the WebBrowser control is allowed only in
the Local Machine and Intranet zones.

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a.

Plugin: Windows

Control ID: 31915772f1fe0768b0448b08e53a608ff61fdb3a7002ec2ec83b854957b32695