1.1 Ensure ESXi is properly patched

Information

VMware Update Manager is a tool used to automate patch management for vSphere
hosts and virtual machines. Creating a baseline for patches is a good way to ensure all hosts
are at the same patch level. VMware also publishes advisories on security patches and offers
a way to subscribe to email alerts for them.

*Rationale*

By staying up to date on ESXi patches, vulnerabilities in the hypervisor can be mitigated. An
educated attacker can exploit known vulnerabilities when attempting to attain access or
elevate privileges on an ESXi host.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Employ a process to keep ESXi hosts up to date with patches in accordance with industry
standards and internal guidelines. Leverage the VMware Update Manager to test and apply patches as they become available.

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2c., CSCv7|3.4

Plugin: VMware

Control ID: 5465ecbdb68e5b79562a47b7e25593a30c97598b27b26ecbf32c36c73d04ec25