8.4.26 Disable VM Console Drag and Drop operations

Information

Disable VM Console Drag and Drop operations.

*Rationale*

By default, the ability to copy and paste text, graphics, and files is disabled, as is the ability
to drag and drop files. When this feature is enabled, you can copy and paste rich text and,
depending on the VMware product, graphics and files from your clipboard to the guest
operating system in a virtual machine. That is, as soon as the console window of a virtual
machine gains focus, nonprivileged users and processes running in the virtual machine can
access the clipboard on the computer where the console window is running.

Solution

To implement the recommended configuration state, run the following PowerCLI
command-# Add the setting to all VMs
Get-VM | New-AdvancedSetting -Name 'isolation.tools.dnd.disable' -value $true

Impact-This is the default setting so functionality remains the same.

Default Value-The prescribed state is the default state.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: VMware

Control ID: 7be98374f0beb965cb44a4c001ac0f7aa8b049e708d51c986df438935acbc1a5