Check: DTOO170 - InfoPath
Microsoft InfoPath 2007 STIG:
DTOO170 - InfoPath
(in versions v4 r13 through v4 r12)
Title
Disable sending "InfoPath 2003" forms as email forms in InfoPath 2007. (Cat II impact)
Discussion
An attacker might target InfoPath 2003 forms to try and compromise an organization's security. InfoPath 2003 did not write a publish location for e-mail forms, which meant that forms could open without a corresponding published location. By default, InfoPath 2007 sends all forms via e-mail using InfoPath e-mail forms integration, including forms that were created using the InfoPath 2003 file format.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms “Disable sending InfoPath 2003 Forms as e-mail forms” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\InfoPath Criteria: If the value DisableInfoPath2003EmailForms is REG_DWORD = 1, this is not a finding.
Fix Text
The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms “Disable sending InfoPath 2003 Forms as e-mail forms” will be set to “Enabled”.
Additional Identifiers
Rule ID: SV-18832r1_rule
Vulnerability ID: V-17668
Group Title: DTOO170 - 2003 forms as email
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |