DTOO295 - InfoPath email forms in Outlook must be disallowed.

Information

Attackers can send users InfoPath email forms in an attempt to gain access to confidential information. Depending on the level of trust of the forms, it might also be possible to gain access to other data automatically. By default, Outlook 2013 uses the InfoPath email forms feature to render forms in Outlook and allows users to fill them out in place.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms 'Disable InfoPath e-mail forms in Outlook' to 'Enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_InfoPath_2013_V1R6_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4), CAT|II, CCI|CCI-001170, Rule-ID|SV-242499r961092_rule, STIG-ID|DTOO295, STIG-Legacy|SV-53432, STIG-Legacy|V-26621, Vuln-ID|V-242499

Plugin: Windows

Control ID: 2160991d8ac7b46d8cf85f009c9a4eb210614466e8aa4bdb868f13eaefe2d684