7.1 Set 'Restrict File Download' to 'Enabled' - explorer.exe

Information

*Description*

This setting can be used to suppress file download prompts that are not user-initiated in
Internet Explorer. If you configure the Internet Explorer Processes (Restrict File
Download) setting to Enabled, file download prompts that are not user-initiated are
blocked for Internet Explorer processes. If you configure this policy setting to Disabled, file
download prompts will occur that are not user-initiated for Internet Explorer processes.
The recommended state for this setting is- Enabled.


*Rationale*

In certain circumstances, Web sites can initiate file download prompts without interaction
from users. This technique can allow Web sites to put unauthorized files on a user's hard
disk drive if they click the wrong button and accept the download.

Solution

To implement the recommended configuration state, set the following Group Policy setting
to Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Security Features\Restrict File Download\Internet Explorer Processes

Impact-None. There is no legitimate reason for a Web site to start transferring a file to a user's
workstation without a user request to do so.

See Also

https://workbench.cisecurity.org/files/1516

Item Details

Audit Name: CIS IE 9 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CSCv6|3.1

Plugin: Windows

Control ID: b062199314e6be2908149adad53037664cb0050a370decddb283adc065f5dabf