Check: DTOO167 - InfoPath
Microsoft InfoPath 2010 STIG:
DTOO167 - InfoPath
(in version v1 r12)
Title
Opening behavior for EMail forms containing code or scripts must be controlled. (Cat II impact)
Discussion
InfoPath notifies and prompts users before opening InfoPath e-mail forms that contain code or script. If this restriction is relaxed, InfoPath will open e-mail forms that contain code or script without prompting users, which could allow malicious code to run on the users' computers.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms "Control behavior when opening InfoPath e-mail forms containing code or script" must be set to "Enabled (Prompt before running". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\14.0\infoPath\security Criteria: If the value EMailFormsRunCodeAndScript is REG_DWORD = 1, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms "Control behavior when opening InfoPath e-mail forms containing code or script" to "Enabled (Prompt before running)".
Additional Identifiers
Rule ID: SV-241897r961779_rule
Vulnerability ID: V-241897
Group Title: SRG-APP-000488
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002460 |
Enforce organization-defined actions prior to executing mobile code. |
Controls
Number | Title |
---|---|
SC-18(4) |
Prevent Automatic Execution |