ESXI5-VM-000005 - The system must explicitly disable any GUI functionality for copy/paste operations

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Copy and paste operations are disabled by default; however, by explicitly disabling this feature it will enable audit controls to check that this setting is correct. Copy, paste, drag and drop, or GUI copy/paste operations between the guest OS and the remote console could provide the means for an attacker to compromise the VM.

Solution

As root, log in to the ESXi host and locate the VM's vmx file.
find / | grep vmx

Add the following to the VM's vmx file.
keyword = 'keyval'

Where:
keyword = isolation.tools.setGUIOptions.enable
keyval = FALSE

See Also

http://iasecontent.disa.mil/stigs/zip/U_ESXi5_Virtual_Machine_V1R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|III, CCI|CCI-000366, Group-ID|V-39446, Rule-ID|SV-51304r1_rule, STIG-ID|ESXI5-VM-000005, Vuln-ID|V-39446

Plugin: VMware

Control ID: 5c4f9050d86756775217d203146698b65191a598ef9fa652b6df4962762f0098