ESXI5-VM-000033 - The system must disable VIX messages from the VM

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The VIX API is a library for writing scripts and programs to manipulate virtual machines. If custom VIX programming is not used in the environment, then consider disabling certain features to reduce the potential for vulnerabilities. The ability to send messages from the VM to the host is one of these features. Note that disabling this feature does NOT adversely affect the functioning of VIX operations that originate outside the guest, so certain VMware and 3rd party solutions that rely upon this capability should continue to work.

Solution

As root, log in to the ESXi host and locate the VM's vmx file.
find / | grep vmx

Add the following to the VM's vmx file.
keyword = 'keyval'

Where:
keyword = isolation.tools.vixMessage.disable
keyval = TRUE

See Also

http://iasecontent.disa.mil/stigs/zip/U_ESXi5_Virtual_Machine_V1R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|III, CCI|CCI-000366, Group-ID|V-39488, Rule-ID|SV-51346r1_rule, STIG-ID|ESXI5-VM-000033, Vuln-ID|V-39488

Plugin: VMware

Control ID: eb0aefbbf2785d74357a987a3a3320c62e5c4e182a6c6c32b08c1476a5ae7561