DTBI340 - Active content from CDs - 'LOCALMACHINE_CD_UNLOCK = 0'.

Information

This policy setting allows you to manage whether users receive a dialog requesting permission for active content on a CD to run. If you enable this policy setting, active content on a CD will run without a prompt. If you disable this policy setting, active content on a CD will always prompt before running. If you do not configure this policy, users can choose whether to be prompted before running active content on a CD.

Solution

Set the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Advanced Page -> 'Allow active content from CDs to run on user machines' to 'Disabled'.

See Also

http://iase.disa.mil/stigs/app_security/browser_guidance/u_microsoft_ie9_v1r5_stig_20130426.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, CSCv6|3.1, Rule-ID|SV-40626r1_rule, STIG-ID|DTBI340, Vuln-ID|V-15497

Plugin: Windows

Control ID: 8da95afc981a2a0f076dbde39fe87e205e4950db33c4af297d2a0bacb981957c