Check: DTOO168 - InfoPath
Microsoft InfoPath 2007 STIG:
DTOO168 - InfoPath
(in versions v4 r13 through v4 r12)
Title
Disable sending the form template with the eMail form in InfoPath. (Cat II impact)
Discussion
By default, InfoPath 2007 allows users to attach form templates when sending e-mail forms. If users are able to open form templates included with e-mail forms, rather than using a cached version that is previously published, an attacker could send a malicious form template with the e-mail form in an attempt to gain access to sensitive information. Note The form template is only opened directly if the form opens with a restricted security level. Otherwise the attachment is actually a link to the published location.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms “Disable sending form template with e-mail forms” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\InfoPath\Deployment Criteria: If the value MailXSNwithXML is REG_DWORD = 0, this is not a finding.
Fix Text
The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms “Disable sending form template with e-mail forms” will be set to “Enabled”.
Additional Identifiers
Rule ID: SV-18830r1_rule
Vulnerability ID: V-17667
Group Title: DTOO168 - Sending templates with email form
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |