Check: DTOO172 - InfoPath
Microsoft InfoPath 2007 STIG:
DTOO172 - InfoPath
(in versions v4 r13 through v4 r12)
Title
Disable eMail forms from the Internet Security Zone for InfoPath. (Cat II impact)
Discussion
InfoPath 2007 e-mail forms can be designed by an external attacker and sent over the Internet as part of a phishing attempt. Users might fill out such forms and provide sensitive information to the attacker. By default, forms that originate from the Internet can be opened, although those forms cannot access content that is stored in a different domain.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms “Disable e-mail forms from the Internet security zone” will be set to “Enabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\InfoPath\Security Criteria: If the value EnableInternetEMailForms is REG_DWORD = 0, this is not a finding.
Fix Text
The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms “Disable e-mail forms from the Internet security zone” will be set to “Enabled”.
Additional Identifiers
Rule ID: SV-18808r1_rule
Vulnerability ID: V-17656
Group Title: DTOO172 - EMail forms from Internet Zone
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |