8.4.21 Disable Host Guest File System Server

Information

Disable unexposed Host Guest File System Server feature.

*Rationale*

Certain automated operations such as automated tools upgrades use a component into the
hypervisor called Host Guest File System (HGFS) and an attacker could potentially use this
to transfer files inside the guest OS.

Solution

To implement the recommended configuration state, run the following PowerCLI
command-# Add the setting to all VMs
Get-VM | New-AdvancedSetting -Name 'isolation.tools.hgfsServerSet.disable' -value
$true

Impact-Setting isolation.tools.hgfsServerSet.disable to true disables registration of the guest's
HGFS server with the host. APIs that use HGFS to transfer files to and from the guest
operating system, such as some VIX commands or the VMware Tools auto-upgrade utility,
will not function.

Default Value-The prescribed state is not the default state.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: VMware

Control ID: 27a00bc56a164eb82db54387a3e27f6b118103c705fc2db87626059258935f82