DTOO168 - InfoPath - Disable sending the form template with the eMail form in InfoPath.

Information

By default, InfoPath 2007 allows users to attach form templates when sending e-mail forms. If users are able to open form templates included with e-mail forms, rather than using a cached version that is previously published, an attacker could send a malicious form template with the e-mail form in an attempt to gain access to sensitive information.
Note The form template is only opened directly if the form opens with a restricted security level. Otherwise the attachment is actually a link to the published location.

Solution

The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms 'Disable sending form template with e-mail forms' will be set to 'Enabled'.

See Also

http://iase.disa.mil/stigs/app_security/office_auto/u_microsoft_office2007_v4r9_stig_20121026.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, Rule-ID|SV-18830r2_rule, STIG-ID|DTOO168, Vuln-ID|V-17667

Plugin: Windows

Control ID: 4e0cee51bb4485622b89cd38261edac7dbe05109a7e801a3abf76bc5007e26a8