VM Tools: guest-8.tools-deactivate-guestoperations

Information

The guest OS must deactivate Guest Operations unless required. Guest Operations are a set of functions that underpin most host-to-guest interaction. Deactivating them reduces attack surface but also drastically reduces functionality. Ensure that your environment does not require these functions. Do not do this on template VMs. For a list of functions see:

https://vdc-download.vmware.com/vmwb-repository/dcr-public/fe08899f-1eec-4d8d-b3bc-a6664c168c2c/7fdf97a1-4c0d-4be0-9d43-2ceebbc174d9/doc/vim.vm.guest.GuestOperationsManager.html

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

C:\\Program Files\\VMware\\VMware Tools\\VMwareToolboxCmd.exe config set guestoperations disabled true

See Also

https://github.com/vmware/vcf-security-and-compliance-guidelines/raw/refs/heads/main/security-configuration-hardening-guide/vsphere/8.0/