Internet Explorer allows active content to be automatically downloaded

Risk Level: Low risk vulnerability  Low

Check or Attack Name: IE active download

Platforms: Windows 95, Windows NT: 4.0
Description:

The web browser allows active content to be automatically downloaded from the HTML page that contains the content. Potentially malicious or virus-infected programs may be stored on the local file system.

Remedy:
  • In Internet Explorer 3.x, from the Options dialog box, go to Security and disable Allow Downloading of Active Content.

    1. Open Internet Explorer 3.x.
    2. From the View menu, select Options.
    3. Click the Security tab.
    4. Disable the Allow Downloading of Active Content option.
    5. Click OK to apply the changes.

  • In Internet Explorer 5.x, from the Internet Options dialog box, go to Security and disable the appropriate settings under Downloads.

    1. Open Internet Explorer 5.x.
    2. From the Tools menu, select Internet Options.
    3. Click the Security tab, and then click Custom Level.
    4. From the Downloads folder, locate the advanced feature and set it to the recommended value.
    5. Click OK to apply the changes.

References:

X-Force Logo
Know Your Risks