Skip to content

InfoPath e-mail forms in Outlook must be disallowed.

An XCCDF Rule

Description

Attackers can send users InfoPath e-mail forms in an attempt to gain access to confidential information. Depending on the level of trust of the forms, it might also be possible to gain access to other data automatically. By default, Outlook 2010 uses the InfoPath e-mail forms feature to render forms in Outlook and allows users to fill them out in place.

Property Value
Responsibility System Administrator

ID
SV-34119r1_rule
Version
DTOO295 - InfoPath
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Set the policy value for User Configuration -> Administrative Templates -> Microsoft InfoPath 2010 -> InfoPath e-mail forms “Disable InfoPath e-mail forms in Outlook” to “Enabled”.