6.7

Table Of Contents
3 Disable hardware devices that are not required.
Include checks for the following devices:
n
Floppy drives
n
Serial ports
n
Parallel ports
n
USB controllers
n
CD-ROM drives
Disable Unused Display Features
Attackers can use an unused display feature as a vector for inserting malicious code into your
environment. Disable features that are not in use in your environment.
Procedure
1 Log in to a vCenter Server system using the vSphere Web Client and find the virtual machine.
a In the Navigator, select VMs and Templates.
b Find the virtual machine in the hierarchy.
2 Right-click the virtual machine and click Edit Settings.
3 Select VM Options.
4 Click Advanced and click Edit Configuration.
5 If appropriate, add or edit the following parameters.
Option Description
svga.vgaonly If you set this parameter to TRUE, advanced graphics functions no longer work.
Only character-cell console mode will be available. If you use this setting,
mks.enable3d has no effect.
Note Apply this setting only to virtual machines that do not need a virtualized
video card.
mks.enable3d Set this parameter to FALSE on virtual machines that do not require 3D
functionality.
Disable Unexposed Features
VMware virtual machines can work both in a vSphere environment and on hosted virtualization platforms
such as VMware Workstation and VMware Fusion. Certain virtual machine parameters do not need to be
enabled when you run a virtual machine in a vSphere environment. Disable these parameters to reduce
the potential for vulnerabilities.
Prerequisites
Turn off the virtual machine.
vSphere Security
VMware, Inc. 133