1.79 (L2) Ensure 'Control use of the Serial API' is set to 'Enable: Do not allow any site to request access to serial ports via the Serial API'

Information

This policy setting configures whether websites can access the systems serial ports.

The recommended state for this setting is: Enable: Do not allow any site to request access to serial ports via the Serial API.

Note: If more granular control is needed (per website) then this setting can be used in combination with the SerialAllowAllPortsForUrls (Allow the Serial API on specific sites), SerialAskForUrls and SerialBlockedForUrls (Block the Serial API on specific sites) settings. For example, SerialAllowAllPortsForUrls can be used to allow serial port access to specific sites. Please see the References Section for more information.

Preventing access to system serial ports may prevent malicious sites from using these ports and accessing attached devices.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enable: Do not allow any site to request access to serial ports via the Serial API :

Microsoft Edge\Control use of the Serial API

Impact:

Legitimate websites that need access to the Serial API will be denied access.

See Also

https://workbench.cisecurity.org/benchmarks/24642

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|CM-11, 800-53|SC-18, CSCv7|7.2

Plugin: Windows

Control ID: bbb62af15d2fadf71e29cb8afe0eec8c78ec7f42870619138fb06ab3d93f7886