[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-98649-7

Platform: cpe:/o:microsoft:windows_10Date: (C)2022-07-05   (M)2023-07-04



Sideloading installs and runs unverified extensions in Microsoft Edge. With this policy, you can specify whether unverified extensions can be sideloaded in Microsoft Edge. If enabled or not configured, sideloading of unverified extensions in Microsoft Edge is allowed. If disabled, sideloading of unverified extensions in Microsoft Edge is not allowed. Extensions can be installed only through Microsoft store (including a store for business), enterprise storefront (such as Company Portal) or PowerShell (using Add-AppxPackage). When disabled, this policy does not prevent sideloading of extensions using Add-AppxPackage via PowerShell. To prevent this, in Group Policy Editor, enable Allows development of Windows Store apps and installing them from an integrated development environment (IDE), which is located at: Computer Configuration > Administrative Templates > Windows Components > App Package Deployment Supported versions: Microsoft Edge on Windows 10, version 1809 Default setting: Disabled or not configured Related policies: - Allows development of Windows Store apps and installing them from an integrated development environment (IDE) - Allow all trusted apps to install​ Fix: (1) GPO: Computer ConfigurationAdministrative TemplatesWindows ComponentsMicrosoft EdgeAllow Sideloading of extension (2) REG: HKEY_LOCAL_MACHINE or HKEY_CURRENT_USERSoftwarePoliciesMicrosoftMicrosoftEdgeExtensions!AllowSideloadingOfExtensions


Parameter:

[enable/disable]


Technical Mechanism:

(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Microsoft Edge\Allow Sideloading of extension (2) REG: HKEY_LOCAL_MACHINE or HKEY_CURRENT_USER\Software\Policies\Microsoft\MicrosoftEdge\Extensions!AllowSideloadingOfExtensions

CCSS Severity:CCSS Metrics:
CCSS Score : 9.0Attack Vector: NETWORK
Exploit Score: 2.2Attack Complexity: HIGH
Impact Score: 6.0Privileges Required: NONE
Severity: CRITICALUser Interaction: NONE
Vector: AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HScope: CHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:81830


OVAL    1
oval:org.secpod.oval:def:81830
XCCDF    1
xccdf_org.secpod_benchmark_general_Windows_10

© SecPod Technologies