8.3.15 Set 'Initialize and script ActiveX controls not marked as safe' to 'Enabled:Disable'

Information

*Description*

This policy setting allows you to manage ActiveX controls not marked as safe. If you enable
this policy setting, ActiveX controls are run, loaded with parameters, and scripted without
setting object safety for untrusted data or scripts. This setting is not recommended, except
for secure and administered zones. The recommended state for this setting is-
Enabled-Disable.

*Rationale*

This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the
Script ActiveX controls marked safe for scripting option. This increases the risk of
malicious code being loaded and executed by the browser.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Initialize and
script ActiveX controls not marked as safe\Initialize and script ActiveX controls not
marked as safe

Then set the Initialize and script ActiveX controls not marked as safe option to
Disable.

Impact-If you enable this policy setting and select Prompt in the drop-down box, users are queried
whether to allow the control to be loaded with parameters or scripted. If you disable this
policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or
scripted. If you do not configure this policy setting, ActiveX controls that cannot be made
safe are not loaded with parameters or scripted.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4)

Plugin: Windows

Control ID: 71f90186bca6094d0a37f1455f502d6104c49589134b312772ab10c05a5b5276