VMware Cloud Community
r_engel
Contributor
Contributor

Removing "Everyone Group" NTFS permissions from Vmwareservice.exe on the Guest OS

Guys

What is the impact (if any) of removing the Everyone Group (NTFS permission) on the C:\Program Files\VMware\VMware Tools\VMwareService.exe? (or its directory)

Does this pose any potential security or stability risk if we remove the permission (if the VM is a Win2k3 Domain Controller)

Cheers

0 Kudos
1 Reply
Texiwill
Leadership
Leadership

Hello,

It will remove functionality for non-Admins logged into the system which would increase security to an extent. Whatever VMware Tools can do through VMwareservice a user can do through code. THe problem is that the VMware Backdoor port is not restricted as well. But what you are trying to do is a good first step. Remove temptation from non-admins.


Best regards, Edward L. Haletky VMware Communities User Moderator, VMware vExpert 2009
Now Available on Rough-Cuts: 'VMware vSphere(TM) and Virtual Infrastructure Security: Securing ESX and the Virtual Environment'[/url]
Also available 'VMWare ESX Server in the Enterprise'[/url]
[url=http://www.astroarch.com/wiki/index.php/Blog_Roll]SearchVMware Pro[/url]|Blue Gears[/url]|Top Virtualization Security Links[/url]|Virtualization Security Round Table Podcast[/url]

--
Edward L. Haletky
vExpert XIV: 2009-2023,
VMTN Community Moderator
vSphere Upgrade Saga: https://www.astroarch.com/blogs
GitHub Repo: https://github.com/Texiwill
0 Kudos