Check: DTOO295 - InfoPath
Microsoft InfoPath 2010 STIG:
DTOO295 - InfoPath
(in version v1 r2)
Title
InfoPath e-mail forms in Outlook must be disallowed. (Cat II impact)
Discussion
Attackers can send users InfoPath e-mail forms in an attempt to gain access to confidential information. Depending on the level of trust of the forms, it might also be possible to gain access to other data automatically. By default, Outlook 2010 uses the InfoPath e-mail forms feature to render forms in Outlook and allows users to fill them out in place.
Check Content
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable InfoPath e-mail forms in Outlook” to “Enabled”.
Additional Identifiers
Rule ID: SV-34119r1_rule
Vulnerability ID: V-26619
Group Title:
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |