VCENTER-000029 - vSphere Client plugins must be verified

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The vCenter Server includes a vSphere Client extensibility framework, which provides the ability to extend the vSphere Client with menu selections or toolbar icons that provide access to vCenter Server add-on components or external, Web-based functionality. vSphere Client plugins or extensions run at the same privilege level as the user. Malicious extensions might masquerade as useful add-ons while compromising the system by stealing credentials or incorrectly configuring the system.

Solution

Disable/remove all listed plug-ins that cannot be verified as distributed from trusted sources: From the vSphere client, connect to the vCenter server. On the menu bar, go to 'Plug-ins >> Manage Plug-ins'. Under Installed Plug-ins, right-click the plug-in of choice and select Disable

See Also

http://iase.disa.mil/stigs/os/virtualization/Pages/index.aspx