DTOO158 - InfoPath - Disable opening of solutions from the Internet Security Zone.

Information

Attackers could use InfoPath 2007 solutions published to Internet Web sites to try to obtain sensitive information from users.
By default, users can open InfoPath solutions that do not contain managed code from sources located in the Internet security zone as defined in the Internet Options dialog box in Internet Explorer.

Solution

The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> Security -> 'Disable opening of solutions from the Internet security zone' will be set to 'Enabled'.

See Also

http://iase.disa.mil/stigs/app_security/office_auto/u_microsoft_office2007_v4r9_stig_20121026.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, Rule-ID|SV-18822r2_rule, STIG-ID|DTOO158, Vuln-ID|V-17663

Plugin: Windows

Control ID: 6a495004fa2387f276bcf1ee075ddc7d9b60294a75a415245f1094ce17a485c0