DTBI114 - Initialize and script ActiveX-Restricted - '1201 = 3'.

Information

ActiveX controls not marked safe for scripting should not be executed. Although this is not a complete security measure for a control to be marked safe for scripting, if a control is not marked safe, it should not be initialized and executed.

Solution

Set the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security Page -> Restricted Sites Zone -> 'Initialize and script ActiveX controls not marked as safe' to 'Enabled', and select 'Disable' from the drop-down box.

See Also

http://iase.disa.mil/stigs/app_security/browser_guidance/u_microsoft_ie9_v1r5_stig_20130426.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(3), CAT|II, Rule-ID|SV-40588r1_rule, STIG-ID|DTBI114, Vuln-ID|V-6291

Plugin: Windows

Control ID: 45d3689680f70da7383207415d0e93ba6dee75bf29faccce402c0a7220506a12