Firefox must be configured to not automatically update installed add-ons and plugins.
An XCCDF Rule
Description
Set this to false to disable checking for updated versions of the Extensions/Themes. Automatic updates from untrusted sites puts the enclave at risk of attack and may override security settings.
- ID
- SV-251549r879587_rule
- Version
- FFOX-00-000005
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Windows group policy:
1. Open the group policy editor tool with "gpedit.msc".
2. Navigate to Policy Path: Computer Configuration\Administrative Templates\Mozilla\Firefox\Extensions
Policy Name: Extension Update
Policy State: Disabled