I am trying to create a DISA STIG compliant 3.5 U4 ESX host and coming across this when running the SRR script against my test host. After trying to search online and through the vmware communities I do not see anything out there where this has been patched/mitigated by vmware.
This finding is listed as a category 1 and could possibly prevent us from getting a ATO ot IATO.
ESX version 3.5 update 4