VMware Security Patching Guidelines for ESX and ESXi
search cancel

VMware Security Patching Guidelines for ESX and ESXi

book

Article ID: 315354

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

VMware has made available patches and update releases to address critical security issues for several products including ESX, ESXi, Workstation, and Player. As a best practice, VMware recommends that customers install all security patches to maximize the protection that VMware provides.

This article lists all latest security patches available for VMware ESXi and VMware ESX as of July 12, 2013. Updating to these patches allows you to achieve maximum protection. This list does not include patches obsoleted by the later patches.

This article does not provide information on VMware Workstation or VMware Player. For information on securing these products as well as information on suggested Update Release levels for ESXi and ESX, see Knowledge Base article: VMware Security Patches Upgrade Guide (2019941) 


Environment

VMware ESXi 4.0.x Installable
VMware vSphere ESXi 5.0
VMware vSphere ESXi 5.5
VMware ESXi 3.5.x Embedded
VMware ESXi 4.1.x Embedded
VMware ESX 4.1.x
VMware ESXi 3.5.x Installable
VMware ESXi 4.0.x Embedded
VMware ESX 4.0.x
VMware vSphere ESXi 5.1
VMware vSphere ESXi 6.0
VMware ESX Server 3.5.x
VMware ESXi 4.1.x Installable

Resolution

Security Patch Table

 
ProductVersionPatch
ESXi6.0
5.5
5.1
5.0
4.1ESXi410-201404401-SG
ESXi410-201312401-SG
ESXi410-201307401-SG
ESXi410-201304401-SG
ESXi410-201301401-SG
ESXi410-201211401-SG
ESXi410-201208101-SG
ESXi410-201208102-SG
ESXi410-201206401-SG
ESXi410-201205401-SG
4.0ESXi400-201404401-SG
ESXi400-201404402-SG
ESXi400-201310401-SG
ESXi400-201305401-SG
ESXi400-201302401-SG
ESXi400-201302402-SG
ESXi400-201302403-SG
ESXi400-201209401-SG
ESXi400-201206401-SG
ESXi400-201205401-SG
ESXi400-201103402-SG
3.5Prerequisite:

June 2011 3.5 U5 roll-up

Subsequent security patches:

ESXe350-201302401-O-SG
VI Client
VMware Tools
Firmware

ESXe350-201206401-O-SG
VI Client
VMware Tools
Firmware

ESXe350-201205401-O-SG
VI Client
VMware Tools
Firmware

ESXe350-201105401-O-SG
VMware Tools
Firmware
 
ESX4.1ESX410-201410401-SG
ESX410-201404401-SG
ESX410-201404402-SG
ESX410-201312401-SG
ESX410-201312403-SG
ESX410-201307401-SG
ESX410-201307402-SG
ESX410-201307403-SG
ESX410-201307404-SG
ESX410-201307405-SG
ESX410-201304401-SG
ESX410-201304402-SG
ESX410-201301401-SG
ESX410-201301402-SG
ESX410-201301403-SG
ESX410-201301405-SG
ESX410-201211401-SG
ESX410-201211402-SG
ESX410-201211405-SG
ESX410-201211407-SG
ESX410-201208101-SG
ESX410-201208102-SG
ESX410-201208103-SG
ESX410-201208104-SG
ESX410-201208105-SG
ESX410-201208106-SG
ESX410-201208107-SG
ESX410-201206401-SG
ESX410-201205401-SG
ESX410-201204402-SG
ESX410-201201407-SG
ESX410-201201406-SG
ESX410-201201405-SG
ESX410-201201404-SG
ESX410-201201402-SG
ESX410-201110225-SG
ESX410-201110224-SG
ESX410-201110207-SG
ESX410-201110206-SG
ESX410-201110204-SG
ESX410-201110201-SG
ESX410-201107406-SG
ESX410-201107405-SG
ESX410-201104407-SG
ESX410-201104404-SG
ESX410-201104403-SG
ESX410-201010413-SG
ESX410-201010412-SG
ESX410-201010409-SG
ESX410-201010404-SG
ESX410-201010402-SG
4.0ESX400-201410401-SG
ESX400-201404401-SG
ESX400-201404402-SG
ESX400-201310401-SG
ESX400-201310402-SG
ESX400-201305401-SG
ESX400-201305402-SG
ESX400-201305403-SG
ESX400-201305404-SG
ESX400-201302401-SG
ESX400-201209401-SG
ESX400-201209402-SG
ESX400-201209404-SG
ESX400-201206401-SG
ESX400-201205401-SG
ESX400-201203407-SG
ESX400-201203406-SG
ESX400-201203405-SG
ESX400-201203404-SG
ESX400-201203403-SG
ESX400-201203402-SG
ESX400-201203401-SG
ESX400-201110410-SG
ESX400-201110409-SG
ESX400-201110408-SG
ESX400-201110406-SG
ESX400-201103407-SG
ESX400-201103405-SG
ESX400-201103404-SG
ESX400-201101404-SG
ESX400-201101402-SG
ESX400-201009411-SG
ESX400-201009407-SG
ESX400-201009406-SG
ESX400-201009402-SG
ESX400-201005407-SG
ESX400-201005405-SG
ESX400-201005404-SG
ESX400-201003403-SG
ESX400-201002407-SG
ESX400-201002406-SG
ESX400-201002404-SG
ESX400-200912404-SG
ESX400-200911239-SG
ESX400-200911234-SG
ESX400-200906411-SG
3.5Prerequisite:

June 2011 3.5 U5 roll-up

Subsequent security patches:

ESX350-201302401-SG
ESX350-201206401-SG
ESX350-201205401-SG
ESX350-201203405-SG
ESX350-201203403-SG
ESX350-201203401-SG
ESX350-201105406-SG
ESX350-201105404-SG
ESX350-201105401-SG
ESX350-201012409-SG
ESX350-201012408-SG
ESX350-201012401-SG
ESX350-201008412-SG
ESX350-201008411-SG
ESX350-201008407-SG
ESX350-201008406-SG
ESX350-201008405-SG
ESX350-201006407-SG
ESX350-201006406-SG
ESX350-201006405-SG
ESX350-201006401-SG

 

Note: Patches are delivered in RPM or VIB format depending on the ESX/ESXi version. VMware packaging policy dictates that the content of a patch RPM or VIB is cumulative throughout the product support life cycle. For example, if you apply a bulletin containing the highest version of an ESX-base VIB for ESXi 5.0, you do not need to apply the lower versions of ESX-base VIB. All VMware patching tools are able to parse the format of a package’s version and determine the latest packages for installation based on the query baseline.

Finding and Downloading Security Patches

You can find and download patches through the Download Patch Portal or vSphere Update Manager.

  • Download Patch Portal. Go to the Download Patch Portal. Use the Search by Product area to select your product and release. Filter your search classification by Security. Your search results should list only bulletin names with an extension of –SG. Search results are in chronological order, from most recent to earliest.

    Use the Download link to download the patches you want to install. If you want only security patches published after a particular ESXi or ESX Update release, download only the patches that have a Release Date later than the Update release running on your hosts. After you download a security patch, follow the installation instructions in the Knowledge Base article that appears in the Bulletin List column of your filtered search.

  • vSphere Update Manager. Go to the Update Manager area of the vSphere Client. Update Manager downloads all patch metadata and displays the patches in the Patch Repository area of the user interface, and you can identify the security patches by –SG extension at the end of the bulletin name. Depending on the Update Manager release, you can also find security patches as follows.

    • Update Manager 5.0. Look in the Category column of the Patch Repository table.

    • Update Manager 4.x and earlier. Look in the Severity column of the Patch Repository table.

Installing ESXi and ESX Patches with Update Manager

You can apply security patches through Update Manager host remediation. To remediate a host in Update Manager, create a fixed baseline that defines the patches you want for remediation or a dynamic baseline that defines the category of patches you want for remediation. Then, remediate your hosts against the baseline.

For usage information, read the "Patch Download and Installation" section of the Knowledge Base article for the patch bulletins.

Installing ESXi and ESX Patches with Command Lines

You can install ESXi and ESX security patches by using Command Line interfaces. The method and commands you use depend on the product release and whether you are working with ESXi hosts or ESX hosts.

Installing Patches on ESXi 5.0 Hosts Using the Command Line

Use esxcli commands to install an entire image profile including your security patches or to install a single VIB that contains the specific patches you want.

  • To install an entire image profile, execute the following esxcli command.

    esxcli software profile update -d <depot bundle file offline or url zip> -p <profile_name>

    Example:
    esxcli software profile update -d /vmfs/volumes/datastore/ESXi500-201205001.zip -p ESXi-5.0.0-20120504001-standard

    Note:
    Each profile is unique to a patch bundle, refer to the patch release KB for each bundle to obtain a list of available profiles to apply.

  • To install a single VIB containing specific security patches, execute the following esxcli command.

    esxcli software vib update -v <viburl>

    Example:
    esxcli software vib update -v http://release/bundle/vib20/tools-light/VMware_locker_tools-light_5.0.0-1.12.653509.vib

For information on using esxcli commands, expand vSphere Command-Line Interface Documentation to view discussions, concepts, and reference material on the vSphere Command-Line Interface. For usage information, read the "Patch Download and Installation" section of the Knowledge Base article for the bulletin.

Installing Patches on ESX 4.x / ESXi 4.x Hosts Using the Command Line

Use esxupdate or vihostupdate to install the patches you want. Your choice depends on whether you are working with ESX hosts or ESXi hosts.

  • You can use esxupdate to install a patch on an ESX 4.x host by executing the following command.

    esxupdate -m <metadata.zip> -b <bulletin id> update

    Example, single patch:
    esxupdate -m http://10.112.69.40/metadata.zip -b ESX410-201205401-SG update

    Example, multiple patches:
    esxupdate -m http://10.112.69.40/metadata.zip -b ESX410-201205401-SG -b ESX410-201204402-SG update

    For information on using esxupdate, see the ESX 4.1 Patch Management Guide or the ESX 4 Patch Management Guide.

  • You can use vihostupdate to install a patch on either an ESXi 4.x host or ESX 4.x host by executing the following command via vSphere CLI prompt.

    vihostupdate --server <server ip> --install -b <bundle zip> -B <bulletin id>

    Examples:
    vihostupdate --server 10.112.69.40 --install -b https://hostupdate.vmware.com/software/VUM/OFFLINE/release-332-20120419-828226/ESX410-201204001.zip -B ESX410-201204402-SG

    vihostupdate --server 10.112.69.40 --install -b C:\Temp\ESX410-201204001.zip -B ESX410-201204402-SG

    For information on using vihostupdate on both ESX/ESXi 4.1 hosts and ESX/ESXi 4.0 hosts, see the vSphere Command-Line Interface Installation and Scripting Guide.

For usage information, read the "Patch Download and Installation" section of the Knowledge Base article for the bulletin.

Installing Patches on ESX 3.5 / ESXi 3.5 Hosts Using the Command Line

Use esxupdate or vihostupdate to install the patches you want. Your choice depends on whether you are working with ESX hosts or ESXi hosts.

  • Use esxupdate to install a patch on an ESX 3.5 host by executing the following command.

    esxupdate -r <url bundle location of the> update

    Example:
    esxupdate -r http://ESXi-3.5.0-expresspatch02/ update

    For information on using esxupdate, see the ESX Server 3 Patch Management Guide.

  • Use vihostupdate to install a patch on an ESXi 3.5 host by executing the following command via vSphere CLI prompt.

    vihostupdate --server <server ip> --install -b <bundle zip>

    For information on using vihostupdate on both ESXi 3.5 hosts, see the ESX Server 3i Configuration Guide.

For usage information, read the "Patch Download and Installation" section of the Knowledge Base article for the bulletin.

Additional Information

For translated versions of this article, see:

Additional Information

How to Download ESXi, vCenter Server Patches in Customer Connect (1021623)