September 2012

Table Of Contents
n
GUESTLIB_HOST_MEM_UNMAPPED_MB
Features not exposed in
vSphere that could
cause vulnerabilities
Because VMware virtual machines run in many VMware products in addition
to vSphere, some virtual machine parameters do not apply in a vSphere
environment. Although these features do not appear in vSphere user interfaces,
disabling them reduces the number of vectors through which a guest operating
system could access a host. Use the following .vmx setting to disable these
features:
isolation.tools.unity.push.update.disable = "TRUE"
isolation.tools.ghi.launchmenu.change = "TRUE"
isolation.tools.ghi.autologon.disable = "TRUE"
isolation.tools.hgfsServerSet.disable = "TRUE"
isolation.tools.memSchedFakeSampleStats.disable = "TRUE"
isolation.tools.getCreds.disable = "TRUE"
Installing and Configuring VMware Tools
48 VMware, Inc.