7.5 Set 'Protection From Zone Elevation' to 'Enabled' - explorer.exe

Information

*Description*

Internet Explorer places restrictions on each Web page that it opens based on the security
zone from which it originates. The recommended state for this setting is- Enabled.

*Rationale*

These restrictions depend on the location of the Web page (such as Internet zone, Intranet
zone, or Local Machine zone). Web pages on a local computer have the fewest security
restrictions and reside in the Local Machine zone, malicious Web pages may attempt to
elevate themselves from their current zone into another zone with higher privileges.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Security Features\Protection From Zone Elevation\Internet Explorer Processes

Impact-If you enable the Internet Explorer Processes (Zone Elevation Protection) setting, any zone
can be protected from zone elevation by Internet Explorer processes. This approach helps
prevent content that runs in one zone from gaining the elevated privileges of another zone.
If you disable this policy setting, no zone receives such protection for Internet Explorer
processes.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-3, CSCv6|3.1

Plugin: Windows

Control ID: 58b95aab5cdc1ed8d7e4c7a43b28ef17a8ce8fb78ec0ac56c59c8c32d2f08598