STIGQter STIGQter: STIG Summary: Microsoft Internet Explorer 11 Security Technical Implementation Guide Version: 1 Release: 19 Benchmark Date: 24 Jul 2020:

Use of the Tabular Data Control (TDC) ActiveX control must be disabled for the Restricted Sites Zone.

DISA Rule

SV-87401r2_rule

Vulnerability Number

V-72763

Group Title

DTBI1120-IE11-Use of the Tabular Data Control (TDC) ActiveX control must be disabled for the Restric

Rule Version

DTBI1120-IE11

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Internet Explorer >> Internet Control Panel >> Security Page >> Restricted Sites Zone, set the "Allow only approved domains to use the TDC ActiveX control" to “Enabled”.

In the Options windows, select "Enable" from the “Only allow approved domains to use the TDC ActiveX control" drop-down box.

Check Contents

Note: Only applies to Windows 10 version 1607 and higher and Windows Server 2016 systems. For other Windows versions, this check is Not Applicable.

In the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Internet Explorer >> Internet Control Panel >> Security Page >> Restricted Sites Zone, verify "Allow only approved domains to use the TDC ActiveX control" is “Enabled”.

In the Options window, verify the “Only allow approved domains to use the TDC ActiveX control" drop-down box is set to “Enable”.

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4

Criteria:

If the value "120c" is REG_DWORD = “3”, this is not a finding.

Vulnerability Number

V-72763

Documentable

False

Rule Version

DTBI1120-IE11

Severity Override Guidance

Note: Only applies to Windows 10 version 1607 and higher and Windows Server 2016 systems. For other Windows versions, this check is Not Applicable.

In the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Internet Explorer >> Internet Control Panel >> Security Page >> Restricted Sites Zone, verify "Allow only approved domains to use the TDC ActiveX control" is “Enabled”.

In the Options window, verify the “Only allow approved domains to use the TDC ActiveX control" drop-down box is set to “Enable”.

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4

Criteria:

If the value "120c" is REG_DWORD = “3”, this is not a finding.

Check Content Reference

M

Target Key

2589

Comments