1.1.18.5 (L1) Ensure 'dom.disable_window_flip' is set to 'Enabled'

Information

This setting allows the configuration of how Firefox handles scripts from raising or lowering browser windows.

The recommended state for this setting is: Enabled

An arbitrary web site raising or lowering the browser window can cause improper input or can help disguise an attack taking place in a lowered window.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Mozilla\Firefox\Preferences (Deprecated)\dom.disable_window_flip

Note: This Group Policy path does not exist by default. An additional Group Policy template ( firefox.admx/adml ) is required - it is available to download at this

link

.

Impact:

Scripts will not be able to raise or lower browser windows.

See Also

https://workbench.cisecurity.org/benchmarks/18454

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CM-7, 800-53|CM-7(1), 800-53|SI-7, 800-53|SI-7(1), CSCv7|7.3

Plugin: Windows

Control ID: 84178b0ba8e2a3740d8d84cda290248eff2b72b76e35ba1e824ecc7ff3ecf371