DTOO170 - InfoPath - Disable sending 'InfoPath 2003' forms as email forms in InfoPath 2007.

Information

An attacker might target InfoPath 2003 forms to try and compromise an organization's security. InfoPath 2003 did not write a publish location for e-mail forms, which meant that forms could open without a corresponding published location.
By default, InfoPath 2007 sends all forms via e-mail using InfoPath e-mail forms integration, including forms that were created using the InfoPath 2003 file format.

Solution

The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms 'Disable sending InfoPath 2003 Forms as e-mail forms' will be set to 'Enabled'.

See Also

http://iase.disa.mil/stigs/app_security/office_auto/u_microsoft_office2007_v4r9_stig_20121026.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CAT|II, Rule-ID|SV-18832r2_rule, STIG-ID|DTOO170, Vuln-ID|V-17668

Plugin: Windows

Control ID: 85aaa66741c93d1b7aa4d9e9bb196bef8f81891dd0a6429bf979c6722242c0a2