1.1.18.6 (L1) Ensure 'dom.disable_window_move_resize' is set to 'Enabled'

Information

This setting allows the configuration of how Firefox handles scripts from moving or resizing browser windows.

The recommended state for this setting is: Enabled

Arbitrary web sites can disguise an attack taking place in a minimized background window by moving or resizing browser windows.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Preferences (Deprecated)\dom.disable_window_move_resize

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

Scripts will not be able to move or resize browser windows.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7, 800-53|CM-7(1), 800-53|SI-7, 800-53|SI-7(1), CSCv7|7.3

Plugin: Windows

Control ID: b884d911854a4f99937abc4289e25f55bff1e4f5d41977c77b95e01386c4915d