ESXI5-VM-000009 - The system must disable HGFS file transfers

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Certain automated operations such as automated tools upgrades, use a component into the hypervisor called 'Host Guest File System' and an attacker could potentially use this to transfer files inside the guest OS.

Solution

As root, log in to the ESXi host and locate the VM's vmx file.
find / | grep vmx

Add the following to the VM's vmx file.
keyword = 'keyval'

Where:
keyword = isolation.tools.hgfsServerSet.disable
keyval = TRUE

See Also

http://iasecontent.disa.mil/stigs/zip/U_ESXi5_Virtual_Machine_V1R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000366, Group-ID|V-39450, Rule-ID|SV-51308r1_rule, STIG-ID|ESXI5-VM-000009, Vuln-ID|V-39450

Plugin: VMware

Control ID: 254975ef14a5d9b47160edf590de7271e1df9c19ebec17e483ff60faf366cc07