6.0.3

Table Of Contents
Disable Unused Display Features
Aackers can use an unused display feature as a vector for inserting malicious code into your environment.
Disable features that are not in use in your environment.
Procedure
1 Find the virtual machine in the vSphere Web Client inventory.
a Select a data center, folder, cluster, resource pool, or host.
b Click the Related Objects tab and click Virtual Machines.
2 Right-click the virtual machine and click Edit .
3 Select VM Options.
4 Click Advanced and click Edit .
5 If appropriate, set the following parameters by adding or editing them if appropriate.
Option Description
svga.vgaonly
If you set this parameter to TRUE, advanced graphics functions no longer
work. Only character-cell console mode will be available. If you use this
seing, mks.enable3d has no eect.
N Apply this seings only to virtual machines that do not need a
virtualized video card.
mks.enable3d
Set this parameter to FALSE on virtual machines that do not require 3D
functionality.
Disable Unexposed Features
VMware virtual machines are designed to work on both vSphere systems and hosted virtualization
platforms such as Workstation and Fusion. Certain virtual machine parameters do not need to be enabled
when you run a virtual machine on a vSphere system. Disable these parameters to reduce the potential for
vulnerabilities.
Prerequisites
Turn o the virtual machine.
Procedure
1 Find the virtual machine in the vSphere Web Client inventory.
a Select a data center, folder, cluster, resource pool, or host.
b Click the Related Objects tab and click Virtual Machines.
2 Right-click the virtual machine and click Edit .
3 Select VM Options.
4 Click Advanced and click Edit .
5 Set the following parameters to TRUE by adding or editing them.
n
isolation.tools.unity.push.update.disable
n
isolation.tools.ghi.launchmenu.change
n
isolation.tools.memSchedFakeSampleStats.disable
n
isolation.tools.getCreds.disable
vSphere Security
222 VMware, Inc.