UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

InfoPath email forms in Outlook must be disallowed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-26619 DTOO295 SV-53389r1_rule ECSC-1 Medium
Description
Attackers can send users InfoPath email forms in an attempt to gain access to confidential information. Depending on the level of trust of the forms, it might also be possible to gain access to other data automatically. By default, Outlook 2013 uses the InfoPath email forms feature to render forms in Outlook and allows users to fill them out in place.
STIG Date
Microsoft InfoPath 2013 STIG 2015-07-24

Details

Check Text ( None )
None
Fix Text (F-46313r1_fix)
Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2013 -> InfoPath e-mail forms "Disable InfoPath e-mail forms in Outlook" to "Enabled".