Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-15773 | DTBF120 | SV-16712r1_rule | Medium |
Description |
---|
When an ActiveX control is referenced in an HTML document, MS Windows checks to see if the control already resides on the client machine. If not, the control can be downloaded from a remote web site. This provides an automated delivery method for mobile code. |
STIG | Date |
---|---|
Mozilla FireFox Security Technical Implementation Guide | 2019-01-02 |
Check Text ( C-16617r1_chk ) |
---|
Open a browser window, type "about:plugins" in the address bar. Criteria: If the Mozilla ActiveX control and plugin support is present and enabled, then this is a finding. |
Fix Text (F-15990r1_fix) |
---|
Remove/uninstall the Mozilla ActiveX plugin |