DTOO170 - InfoPath 2003 forms as email forms in InfoPath 2013 must be disallowed.

Information

An attacker might target InfoPath 2003 forms to try and compromise an organization's security. InfoPath 2003 did not write a published location for email forms, which means forms could open without a corresponding published location.
By default, InfoPath sends all forms via email using InfoPath email forms integration, including forms created using the InfoPath 2003 file format.

Solution

Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms 'Disable sending InfoPath 2003 Forms as e-mail forms' to 'Enabled'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_InfoPath_2013_V1R6_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18(4), CAT|II, CCI|CCI-001170, Rule-ID|SV-242493r961092_rule, STIG-ID|DTOO170, STIG-Legacy|SV-53389, STIG-Legacy|V-26619, Vuln-ID|V-242493

Plugin: Windows

Control ID: 2cf4aee225677a0b00ad8a739dfc01fd53c8ee8ff01db0aa20c5dfc24a27e9a1