VM : restrict-host-info

Information

If set to TRUE a VM can obtain detailed information about the physical host. The default value for the parameter is FALSE. This setting should not be TRUE unless a particular VM requires this information for performance monitoring. An adversary potentially can use this information to inform further attacks on the host.

Solution

Set tools.guestlib.enableHostInfo to false in the virtual machine configuration file.

See Also

https://www.vmware.com/files/xls/hardeningguide-vsphere5-5-ga-released.xlsx

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-4

Plugin: VMware

Control ID: 2d9265dffbd823c051356d0e55a01cf2a0c1fa2be9b129a1c6f90d8b7b5c7e6b