6.7

Table Of Contents
Procedure
1 Log in to a vCenter Server system using the vSphere Web Client and find the virtual machine.
a In the Navigator, select VMs and Templates.
b Find the virtual machine in the hierarchy.
2 Right-click the virtual machine and click Edit Settings.
3 Select VM Options.
4 Click Advanced and click Edit Configuration.
5 Set the following parameters to TRUE by adding or editing them.
n
isolation.tools.unity.push.update.disable
n
isolation.tools.ghi.launchmenu.change
n
isolation.tools.memSchedFakeSampleStats.disable
n
isolation.tools.getCreds.disable
n
isolation.tools.ghi.autologon.disable
n
isolation.bios.bbs.disable
n
isolation.tools.hgfsServerSet.disable
6 Click OK.
Disable VMware Shared Folders Sharing Host Files to the Virtual Machine
In high-security environments, you can disable certain components to minimize the risk that an attacker
can use the host guest file system (HGFS) to transfer files inside the guest operating system.
Modifying the parameters described in this section affects only the Shared Folders feature and does not
affect the HGFS server running as part of tools in the guest virtual machines. Also, these parameters do
not affect the auto-upgrade and VIX commands that use the tools' file transfers.
Procedure
1 Log in to a vCenter Server system using the vSphere Web Client and find the virtual machine.
a In the Navigator, select VMs and Templates.
b Find the virtual machine in the hierarchy.
2 Right-click the virtual machine and click Edit Settings.
3 Select VM Options.
4 Click Advanced and click Edit Configuration.
5 Verify that the isolation.tools.hgfsServerSet.disable parameter is set to TRUE.
A setting of TRUE prevents the VMX process from receiving a notification from each tool's service,
daemon, or upgrader processes of its HGFS server capability.
vSphere Security
VMware, Inc. 134