UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

InfoPath 2003 forms as email forms in InfoPath 2010 must be disallowed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-17668 DTOO170 - InfoPath SV-33646r1_rule Medium
Description
An attacker might target InfoPath 2003 forms to try and compromise an organization's security. InfoPath 2003 did not write a published location for e-mail forms, which means forms could open without a corresponding published location. By default, InfoPath sends all forms via e-mail using InfoPath e-mail forms integration, including forms created using the InfoPath 2003 file format.
STIG Date
Microsoft InfoPath 2010 STIG 2018-04-03

Details

Check Text ( C-34107r1_chk )
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable sending InfoPath 2003 Forms as e-mail forms” must be set to “Enabled”.

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\14.0\infopath

Criteria: If the value DisableInfoPath2003EmailForms is REG_DWORD = 1, this is not a finding.

Fix Text (F-29787r1_fix)
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable sending InfoPath 2003 Forms as e-mail forms” to “Enabled”.