6.5.1

Table Of Contents
Disable Unexposed Features
VMware virtual machines can work both in a vSphere environment and on hosted virtualization platforms
such as VMware Workstation and VMware Fusion. Certain virtual machine parameters do not need to be
enabled when you run a virtual machine in a vSphere environment. Disable these parameters to reduce
the potential for vulnerabilities.
Prerequisites
Turn off the virtual machine.
Procedure
1 Log in to a vCenter Server system using the vSphere Web Client and find the virtual machine.
a In the Navigator, select VMs and Templates.
b Find the virtual machine in the hierarchy.
2 Right-click the virtual machine and click Edit Settings.
3 Select VM Options.
4 Click Advanced and click Edit Configuration.
5 Set the following parameters to TRUE by adding or editing them.
n
isolation.tools.unity.push.update.disable
n
isolation.tools.ghi.launchmenu.change
n
isolation.tools.memSchedFakeSampleStats.disable
n
isolation.tools.getCreds.disable
n
isolation.tools.ghi.autologon.disable
n
isolation.bios.bbs.disable
n
isolation.tools.hgfsServerSet.disable
6 Click OK.
Disable HGFS File Transfers
Certain operations such as automated VMware Tools upgrades use a component in the hypervisor called
host guest file system (HGFS). In high-security environments, you can disable this component to
minimize the risk that an attacker can use HGFS to transfer files inside the guest operating system.
Procedure
1 Log in to a vCenter Server system using the vSphere Web Client and find the virtual machine.
a In the Navigator, select VMs and Templates.
b Find the virtual machine in the hierarchy.
2 Right-click the virtual machine and click Edit Settings.
vSphere Security
VMware, Inc. 136