Zone ActiveX safe scripting enabled

Risk Level: Low risk vulnerability  Low

Check or Attack Name: Zone safe scripting enabled

Platforms: Windows NT, Internet Explorer
Description:

The security zone settings allow ActiveX controls marked as safe to be scripted from the URL security zone of the HTML page that contains the script. Potentially malicious scripts containing ActiveX controls may be automatically executed by the web browser.

Remedy:

Depending on your version, select one of the following choices in Internet Explorer:

  • For Internet Explorer 4.x:

    1. Open Internet Explorer 4.x.
    2. From the View menu, select Internet Options.
    3. Click the Security tab.
    4. Select the appropriate Zone.
    5. Click Custom (for expert users).
    6. Click Settings.
    7. Disable Script ActiveX controls marked safe for scripting.
    8. Click OK twice to apply the changes.

  • For Internet Explorer 5.x:

    1. Open Internet Explorer 5.x.
    2. From the Tools menu, select Internet Options.
    3. Click the Security tab.
    4. Select the appropriate Zone.
    5. Click Custom Level.
    6. In the ActiveX controls and plug-ins area, disable Script ActiveX controls marked safe for scripting.
    7. Click OK twice to apply the changes.

References:

X-Force Logo
Know Your Risks