DTOO171 - InfoPath - Disable eMail forms running in Restricted Security Level.

Information

InfoPath 2007 forms that run with the restricted security level can only access data that is stored on the forms. However, a malicious user could still send an e-mail form that runs with the restricted security level in an attempt to access sensitive information provided by users.
By default InfoPath 2007 e-mail forms running with the restricted security level can be opened.

Solution

The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms 'Disable e-mail forms running in restricted security level' will be set to 'Enabled'.

See Also

http://iase.disa.mil/stigs/app_security/office_auto/u_microsoft_office2007_v4r9_stig_20121026.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, Rule-ID|SV-18810r2_rule, STIG-ID|DTOO171, Vuln-ID|V-17657

Plugin: Windows

Control ID: dc3a211a8547927d0f108c3ab894c51abedc5acf1a8f0118939edcdeb272d6d7