ESXI5-VM-000006 - The system must explicitly disable paste operations

Information

Copy and paste operations are disabled by default; however, by explicitly disabling this feature it will enable audit controls to check that this setting is correct. Copy, paste, drag and drop, or GUI copy/paste operations between the guest OS and the remote console could provide the means for an attacker to compromise the VM.

Solution

As root, log in to the ESXi host and locate the VM's vmx file.
find / | grep vmx

Add the following to the VM's vmx file.
keyword = 'keyval'

Where:
keyword = isolation.tools.paste.disable
keyval = TRUE

See Also

http://iasecontent.disa.mil/stigs/zip/U_ESXi5_Virtual_Machine_V1R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|III, CCI|CCI-000366, Group-ID|V-39447, Rule-ID|SV-51305r1_rule, STIG-ID|ESXI5-VM-000006, Vuln-ID|V-39447

Plugin: VMware

Control ID: 15454b8737c42757d7cb8f009a474154b6b442d1cab6580147bb93d9f194718c