Skip to content

InfoPath 2003 forms as email forms in InfoPath 2010 must be disallowed.

An XCCDF Rule

Description

An attacker might target InfoPath 2003 forms to try and compromise an organization's security. InfoPath 2003 did not write a published location for e-mail forms, which means forms could open without a corresponding published location. By default, InfoPath sends all forms via e-mail using InfoPath e-mail forms integration, including forms created using the InfoPath 2003 file format.

Property Value
Responsibility System Administrator

ID
SV-33646r1_rule
Version
DTOO170 - InfoPath
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable sending InfoPath 2003 Forms as e-mail forms” to “Enabled”.