DTOO173 - InfoPath - Disable email forms from the Full Trust Security Zone.

Information

InfoPath provides three security levels for form templates: Restricted, Domain, and Full Trust. The security levels determine whether a form template can access data on other domains, or access files and settings on your computer. Fully trusted forms have a Full Trust security level, and can access files and settings on users' computers. The form template for these forms must be digitally signed with a trusted root certificate, or installed on users' computers.
By default, InfoPath 2007 can open e-mail forms with full trust. If an attacker designs and sends a dangerous fully trusted e-mail form, it could affect users' computers or give the attacker access to sensitive information.

Solution

The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms 'Disable e-mail forms from the Full Trust security zone' will be set to 'Enabled'.

See Also

http://iase.disa.mil/stigs/app_security/office_auto/u_microsoft_office2007_v4r9_stig_20121026.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, Rule-ID|SV-18806r2_rule, STIG-ID|DTOO173, Vuln-ID|V-17655

Plugin: Windows

Control ID: f2de11ff0c04f53f91c7f2a324dc3faf8b1d43c005857ae2f7a0ee42127a9ab0