| VID |
28615 |
| Severity |
20 |
| Port |
139,445 |
| Protocol |
TCP |
| Class |
SMB |
| Detailed Description |
Internet Explorer 'File Download' option is set less than the value defined in the security policy. Malicious or virus-infected program may be automatically downloaded on the local computer, although the user dose not know. Internet Explorer includes five predefined zones: Internet, Local Intranet, Trusted Sites, Restricted Sites, and My Computer. User can set the security options that user wants for each zone, and then add or remove Web sites from the zones, depending on your level of trust in a Web site. This option for each security zone manages whether or not files should be directly downloaded from the HTML page including the download link in the security zone.
* Note: This check requires an account with Guest or upper privileges which can access the registry of the remote host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts. Unless the user applies the new policy of security zones, the default value of this option is set to the settings value of the security zone in Internet Explorer 5.
* References: http://support.microsoft.com/default.aspx?scid=kb;EN-US;182569 http://support.microsoft.com/default.aspx?scid=kb;EN-US;174360 http://support.microsoft.com/default.aspx?scid=kb;EN-US;300443 http://www.microsoft.com/technet/archive/ie/reskit/ie4/part7/part7a.asp
* Platforms Affected: Microsoft Internet Explorer Any version Windows Any version |
| Recommendation |
Configure the security settings within Internet Explorer to satisfy the recommended policy below or your security policy by performing the following steps:
For Internet Explorer 4: 1. Open Internet Explorer. 2. From the View menu, select Internet Options. 3. Click the "Security" tab and then select the appropriate zone. 4. Click the "Custom" and click the "Setting". 5. Set the "File Download" to your security policy. Or set back to the recommended policy as the followings: - Local Intranet, Internet, Trusted Sites: Allow - Restricted Sites: Prompt
For Internet Explorer 5 - 10: 1. Open Internet Explorer. 2. From the Tools menu, select Internet Options. 3. Click the ¡°Security¡± tab and then select the appropriate zone. 4. Click the "Custom Level". 5. In the Download area, set the "File Download" to your security policy. Or set back to the recommended policy as the followings: - Local Intranet, Internet, Trusted Sites: Allow - Restricted Sites: Disallow |
| Related URL |
(CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
375 (ISS) |
|