Check: DTOO167 - InfoPath
Microsoft InfoPath 2007 STIG:
DTOO167 - InfoPath
(in versions v4 r13 through v4 r12)
Title
Control Forms Opening behavior for EMail forms containing code or scripts - InfoPath. (Cat II impact)
Discussion
By default, InfoPath 2007 notifies and prompts users before opening InfoPath e-mail forms that contain code or script. If this restriction is relaxed, InfoPath will open e-mail forms that contain code or script without prompting users, which could allow malicious code to run on the users' computers.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms “Control behavior when opening InfoPath e-mail forms containing code or script” will be set to “Enabled (Prompt before running)”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\InfoPath\Security Criteria: If the value EMailFormsRunCodeAndScript is REG_DWORD = 1, this is not a finding.
Fix Text
The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms “Control behavior when opening InfoPath e-mail forms containing code or script” will be set to “Enabled (Prompt before running)”.
Additional Identifiers
Rule ID: SV-18699r1_rule
Vulnerability ID: V-17580
Group Title: DTOO167 - Forms Opening behavior - EMail /w code
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |