7.8 Set 'Protection From Zone Elevation' to 'Enabled'

Information



Internet Explorer places restrictions on each Web page that it opens based on the security
zone from which it originates. The recommended state for this setting is- Enabled.


*Rationale*

These restrictions depend on the location of the Web page (such as Internet zone, Intranet
zone, or Local Machine zone). Web pages on a local computer have the fewest security
restrictions and reside in the Local Machine zone, malicious Web pages may attempt to
elevate themselves from their current zone into another zone with higher privileges.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Security Features\Protection From Zone Elevation\Internet Explorer Processes

Impact-If you enable the Internet Explorer Processes (Zone Elevation Protection) setting, any zone
can be protected from zone elevation by Internet Explorer processes. This approach helps
prevent content that runs in one zone from gaining the elevated privileges of another zone.
If you disable this policy setting, no zone receives such protection for Internet Explorer
processes.

Default Value-Enabled
8 Security Zones

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-3, CSCv6|3.1

Plugin: Windows

Control ID: 6d0abdc9cb04625df0b4701227737cd3c411d1c5467f7e7d86306f3a017c1dcb