UCF STIG Viewer Logo

InfoPath e-mail forms in Outlook must be disallowed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-26619 DTOO295 - InfoPath SV-34119r1_rule Medium
Description
Attackers can send users InfoPath e-mail forms in an attempt to gain access to confidential information. Depending on the level of trust of the forms, it might also be possible to gain access to other data automatically. By default, Outlook 2010 uses the InfoPath e-mail forms feature to render forms in Outlook and allows users to fill them out in place.
STIG Date
Microsoft InfoPath 2010 STIG 2018-04-03

Details

Check Text ( C-34215r1_chk )
The policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable InfoPath e-mail forms in Outlook” must be set to “Enabled”.

Procedure: Use the Windows Registry Editor to navigate to the following key:

HKCU\Software\Policies\Microsoft\Office\14.0\outlook\options\mail

Criteria: If the value DisableInfopathForms is REG_DWORD = 1, this is not a finding.
Fix Text (F-29906r1_fix)
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable InfoPath e-mail forms in Outlook” to “Enabled”.