8.4.7 Disable Guest Host Interaction Protocol Handler

Information

Disable Guest Host Interaction Protocol Handle to reduce opportunity for vulnerabilities.

*Rationale*

Because VMware virtual machines are designed to work on both vSphere as well as hosted
virtualization platforms such as Workstation and Fusion, there are some VMX parameters
that don't apply when running on vSphere. Although the functionality governed by these
parameters is not exposed on ESX, explicitly disabling them will reduce the potential for
vulnerabilities. Disabling these features reduces the number of vectors through which a
guest can attempt to influence the host, and thus may help prevent successful exploits.

Solution

To implement the recommended configuration state, run the following PowerCLI
command-# Add the setting to all VMs
Get-VM | New-AdvancedSetting -Name 'isolation.tools.ghi.protocolhandler.info.disable' -value $true

Impact-Some automated tools and process may cease to function.

Default Value-The prescribed state is not the default state.

See Also

https://workbench.cisecurity.org/files/902

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: VMware

Control ID: ad193e603e9133e764f5da19bddd83d03d0f43aa9923c4465cff01a0eb49dcdf