Check: DTOO295
Microsoft InfoPath 2013 STIG:
DTOO295
(in versions v1 r5 through v1 r4)
Title
InfoPath email forms in Outlook must be disallowed. (Cat II impact)
Discussion
Attackers can send users InfoPath email forms in an attempt to gain access to confidential information. Depending on the level of trust of the forms, it might also be possible to gain access to other data automatically. By default, Outlook 2013 uses the InfoPath email forms feature to render forms in Outlook and allows users to fill them out in place.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable InfoPath e-mail forms in Outlook" must be set to "Enabled". Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\15.0\outlook\options\mail Criteria: If the value DisableInfopathForms is REG_DWORD = 1, this is not a finding.
Fix Text
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable InfoPath e-mail forms in Outlook" to "Enabled".
Additional Identifiers
Rule ID: SV-53389r1_rule
Vulnerability ID: V-26619
Group Title: DTOO295 - InfoPath e-mail forms in Outlook
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001170 |
The information system prevents the automatic execution of mobile code in organization-defined software applications. |
Controls
Number | Title |
---|---|
SC-18 (4) |
Prevent Automatic Execution |