1.1 Keep ESXi system properly patched

Information

VMware Update Manager is a tool used to automate patch management for vSphere hosts
and Virtual machines. Creating a baseline for patches is a good way to ensure all hosts are
at the same patch level.

*Rationale*

By staying up to date on ESXi patches, vulnerabilities in the hypervisor can be mitigated. An
educated attacker can exploit known vulnerabilities when attempting to attain access or
elevate privileges on an ESXi host.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Leverage the VMware Update Manager to test and apply patches as they become available.

Impact-VMs must be powered off in order to update the host ESXi server.

See Also

https://workbench.cisecurity.org/files/145

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2

Plugin: VMware

Control ID: c15ad7bf4ce80c93b877dcf249cf20b3df55a77d697e95ae1cafd446ec662480