1.4.5 (L2) Ensure 'Control use of the File System API for reading' is set to 'Enabled: Don't allow any site to request read access to files and directories via the File System API'

Information

This policy setting determines whether websites can ask for read access to the host operating system's file system using the File System API.

The recommended state for this setting is: Enabled: Don't allow any site to request read access to files and directories via the File System API.

There is a large category of attack vectors that are opened by allowing web applications access to files. By setting this policy to Enabled: Don't allow any site to request read access to files and directories implements additional protections to safeguard against accidental sharing of sensitive information contained in local files.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enabled: Don't allow any site to request read access to files and directories via the File System API :

Microsoft Edge\Content settings\Control use of the File System API for reading

Impact:

Users with creative roles that require the File System API access permission to read files for photo, video, and text editors or for creating integrated development environments will need additional permissions granted based on their role.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|7.2

Plugin: Windows

Control ID: eb6dea921ebe3bf5b5d243a19e25c0423bc16ad0ad7194ccea00f2837808c8dc