UCF STIG Viewer Logo

The software channel permissions must be configured with High Safety (Restricted Sites zone).


Overview

Finding ID Version Rule ID IA Controls Severity
V-6305 DTBI130 SV-40615r1_rule DCMC-1 Medium
Description
Software Channel permissions must have a level of protection based upon the site being accessed. This policy setting allows you to manage software channel permissions. Any setting lower than High Safety could cause a user to install software that includes malicious code.
STIG Date
Microsoft Internet Explorer 9 Security Technical Implementation Guide 2012-11-29

Details

Check Text ( C-39358r1_chk )
The policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security Page -> Restricted Sites Zone -> “Software channel permissions” must be “Enabled” and “High Safety” selected from the drop-down box.

Procedure: Use the Windows Registry Editor to navigate to the following key: HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4

Criteria: If the value 1E05 is REG_DWOD = 65536 (decimal), this is not a finding.
Fix Text (F-34469r1_fix)
Set the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security Page -> Restricted Sites Zone -> “Software channel permissions” to “Enabled” and select “High Safety” from the drop-down box.