VM : disable-hgfs

Information

Certain automated operations such as automated tools upgrades use a component into the hypervisor called 'Host Guest File System' and an attacker could potentially use this to transfer files inside the guest OS.

Solution

Set isolation.tools.hgfsServerSet.disable to true in the virtual machine configuration file.

See Also

https://www.vmware.com/files/xls/hardeningguide-vsphere5-5-ga-released.xlsx

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: VMware

Control ID: d4de672d38fa06d43d7589b7aed2ee27f7774c1265c487bffe2f1216ef41d759