DTOO167 - InfoPath - Control Forms Opening behavior for EMail forms containing code or scripts.

Information

By default, InfoPath 2007 notifies and prompts users before opening InfoPath e-mail forms that contain code or script. If this restriction is relaxed, InfoPath will open e-mail forms that contain code or script without prompting users, which could allow malicious code to run on the users' computers.

Solution

The policy value for User Configuration -> Administrative Templates -> Microsoft Office InfoPath 2007 -> InfoPath e-mail forms 'Control behavior when opening InfoPath e-mail forms containing code or script' will be set to 'Enabled (Prompt before running)'.

See Also

http://iase.disa.mil/stigs/app_security/office_auto/u_microsoft_office2007_v4r9_stig_20121026.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4), CAT|II, Rule-ID|SV-18699r2_rule, STIG-ID|DTOO167, Vuln-ID|V-17580

Plugin: Windows

Control ID: fe5c9140629551e0ecf387d1479e07788672e136349b8a17936c996e287c2aa8