STIGQter STIGQter: STIG Summary: Mozilla Firefox Security Technical Implementation Guide Version: 6 Release: 8 Benchmark Date: 01 Jul 2026:

Firefox must be configured to not automatically execute or download MIME types that are not authorized for auto-download.

DISA Rule

SV-251550r961194_rule

Vulnerability Number

V-251550

Group Title

SRG-APP-000278

Rule Version

FFOX-00-000006

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove any unauthorized extensions from the auto-download list.

Check Contents

Type "about:preferences" in the browser address bar.

Type "Applications" in the Find bar in the upper-right corner.

Determine if any of the following file extensions are listed: HTA, JSE, JS, MOCHA, SHS, VBE, VBS, SCT, WSC, FDF, XFDF, LSL, LSO, LSS, IQY, RQY, DOS, BAT, PS, EPS, WCH, WCM, WB1, WB3, WCH, WCM, AD.

If the entry exists and the "Action" is "Save File" or "Always Ask", this is not a finding.

If an extension exists and the entry in the Action column is associated with an application that does/can execute the code, this is a finding.

Vulnerability Number

V-251550

Documentable

False

Rule Version

FFOX-00-000006

Severity Override Guidance

Type "about:preferences" in the browser address bar.

Type "Applications" in the Find bar in the upper-right corner.

Determine if any of the following file extensions are listed: HTA, JSE, JS, MOCHA, SHS, VBE, VBS, SCT, WSC, FDF, XFDF, LSL, LSO, LSS, IQY, RQY, DOS, BAT, PS, EPS, WCH, WCM, WB1, WB3, WCH, WCM, AD.

If the entry exists and the "Action" is "Save File" or "Always Ask", this is not a finding.

If an extension exists and the entry in the Action column is associated with an application that does/can execute the code, this is a finding.

Check Content Reference

M

Target Key

5446