[{"data":1,"prerenderedAt":1464},["ShallowReactive",2],{"blog-\u002Fen\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi":3,"blog-\u002Fen\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi-surround":1406,"blog-\u002Fen\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi-certifications":1463},{"id":4,"title":5,"body":6,"categories":1394,"cover":1395,"cover_contain":1396,"credly_badge_id":1394,"date":1397,"description":1398,"extension":1399,"meta":1400,"navigation":1396,"path":1401,"related_certifications":1394,"seo":1402,"slug":1403,"stem":1404,"__hash__":1405},"blog\u002Fen\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi.md","Security Patches and Updates on VMware ESXi 5",{"type":7,"value":8,"toc":1382},"minimark",[9,14,18,22,107,112,119,228,232,260,291,303,307,367,375,382,399,403,446,468,474,479,482,487,520,526,568,589,592,622,629,633,650,665,668,952,955,961,964,982,1022,1025,1053,1074,1084,1117,1125,1145,1169,1176,1188,1196,1205,1224,1238,1271,1278,1292,1325,1352,1371,1375,1378],[10,11,13],"h2",{"id":12},"real-world-use-case","Real-world use case",[15,16,17],"p",{},"You need to keep several ESXi 5.x hosts up to date on the security side: here's how to apply patches easily.",[10,19,21],{"id":20},"vmware-esxi-and-it-security","VMware ESXi and IT security",[15,23,24,28,29,32,33,36,39,40,43,44,47,48,50,51,54,55,58,59,62,64,65,68,69,72,73,76,77,79,80,82,83,79,86,88,89,92,93,96,97,68,100,79],{},[25,26,27],"strong",{},"IT systems"," are prone to ",[25,30,31],{},"security holes",", not surprising, is it?",[34,35],"br",{},[25,37,38],{},"VMware ESXi"," is also affected by ",[25,41,42],{},"vulnerabilities",", which are later ",[25,45,46],{},"fixed"," by the vendor.",[34,49],{},"\nToday, it's important to follow a ",[25,52,53],{},"product's evolution"," in order to ",[25,56,57],{},"close"," its ",[25,60,61],{},"holes.",[34,63],{},"\nWe'll take the example of an ",[25,66,67],{},"ESXi 5.1 template",": ",[25,70,71],{},"OVH."," We're going to ",[25,74,75],{},"patch"," the ",[25,78,42],{},".",[34,81],{},"\nThe system will then become a bit more reliable and make things harder for ",[25,84,85],{},"potential attackers",[34,87],{},"\nThe ",[25,90,91],{},"discovery"," of the ",[25,94,95],{},"Heartbleed vulnerability"," also affected version 5.5 of ",[25,98,99],{},"ESXi",[101,102,106],"a",{"href":103,"rel":104},"http:\u002F\u002Fblogmotion.fr\u002Fsysteme\u002Fpatch-vsphere-11828",[105],"nofollow","vulnerability example",[108,109,111],"h3",{"id":110},"understanding-whats-at-stake","Understanding what's at stake:",[15,113,114,115,118],{},"Before diving into fixing vulnerabilities on an ",[25,116,117],{},"infrastructure",", it's important to know a few steps and keep certain points in mind:",[120,121,122,130,140,150,161,192,203,216,225],"ul",{},[123,124,125,126,129],"li",{},"Fixing vulnerabilities is a ",[25,127,128],{},"multi-step process",", and the steps need to be done in order.",[123,131,132,133,76,136,139],{},"Before performing them, you need to ",[25,134,135],{},"understand",[25,137,138],{},"process"," as a whole.",[123,141,142,145,146,149],{},[25,143,144],{},"The steps"," are ",[25,147,148],{},"reversible",", a patch can be uninstalled.",[123,151,152,153,156,157,160],{},"If you use ",[25,154,155],{},"plugins",", check their ",[25,158,159],{},"compatibility"," with future updates.",[123,162,163,164,76,167,170,171,174,175,178,179,170,182,178,185,170,188,191],{},"You also need to ",[25,165,166],{},"master",[25,168,169],{},"technical"," ",[25,172,173],{},"language"," (",[25,176,177],{},"VIB",", ",[25,180,181],{},"image",[25,183,184],{},"profile",[25,186,187],{},"software",[25,189,190],{},"repository",", etc…).",[123,193,194,195,198,199,202],{},"Take ",[25,196,197],{},"precautions"," (you can never repeat this enough): ",[25,200,201],{},"back up your VMs","!",[123,204,205,206,170,209,212,213],{},"Understand the ",[25,207,208],{},"esxcli",[25,210,211],{},"command"," and its ",[25,214,215],{},"parameters.",[123,217,218,219,68,222,79],{},"Check your ",[25,220,221],{},"VIB checksums",[25,223,224],{},"run a test before deploying",[123,226,227],{},"Apply the patch or update to your host.",[108,229,231],{"id":230},"the-problem-at-hand","The problem at hand:",[15,233,234,235,237,238,241,242,245,246,249,250,79,253,255,256,259],{},"Our task is to ",[25,236,75],{}," a ",[25,239,240],{},"hypervisor"," running ",[25,243,244],{},"VMware ESXi 5.1"," to ",[25,247,248],{},"5.1U1",", then ",[25,251,252],{},"U2",[34,254],{},"\nFor the ",[25,257,258],{},"update process"," (ESXi 5.1 to 5.1U1), you need to ask yourself certain questions:",[261,262,263,270,280],"ol",{},[123,264,265,266,269],{},"Is my ESXi server currently in production? Can it go into ",[25,267,268],{},"maintenance mode","?",[123,271,272,273,276,277,269],{},"What are the components that make up ",[25,274,275],{},"my server","? Are they ",[25,278,279],{},"compatible with ESXi 5.1",[123,281,282,283,286,287,290],{},"Are the ",[25,284,285],{},"drivers"," available for the ",[25,288,289],{},"future ESXi 5.1 system"," I want to deploy?",[15,292,293,294,79,297,299,302],{},"This kind of question is essential before starting any kind of ",[25,295,296],{},"migration",[34,298],{},[25,300,301],{},"Adjust your updates according to your server",", in my case, I use a dedicated mSP 2013 server.",[108,304,306],{"id":305},"listing-cves","Listing CVEs",[15,308,309,310,315,316,321,323,324,326,327,79,330,332,335,336,339,340,342,343,79,348,350,351,354,355,357,358,361,362,79],{},"There are quite a few CVE websites, such as: ",[101,311,314],{"href":312,"rel":313},"https:\u002F\u002Fcve.mitre.org\u002F",[105],"CVE.mitre"," and ",[101,317,320],{"href":318,"rel":319},"http:\u002F\u002Fcert.ssi.gouv.fr\u002Fsite\u002FCERTFR-2014-ALE-003\u002F",[105],"CERT SSI gouv fr.",[34,322],{},"\nWhen a CVE is publicly disclosed, there's usually a ",[25,325,75],{}," to close the ",[25,328,329],{},"hole",[34,331],{},[25,333,334],{},"VMware"," has a ",[25,337,338],{},"public portal"," for its ",[25,341,42],{},", available at this address: ",[101,344,347],{"href":345,"rel":346},"https:\u002F\u002Fwww.vmware.com\u002Fpatchmgr\u002FfindPatch.portal",[105],"VMware portal",[34,349],{},"\nIn our case, we're going to ",[25,352,353],{},"list the publicly known CVEs"," after August 29, 2012 (release date of ",[25,356,38],{}," 5.1) from the ",[25,359,360],{},"CVEdetails"," website, available at this address: ",[101,363,366],{"href":364,"rel":365},"http:\u002F\u002Fwww.cvedetails.com\u002Fvulnerability-search.php",[105],"vulnerability",[15,368,369,370,79],{},"The list of known CVEs for vendor VMware and product ESXi is at ",[101,371,374],{"href":372,"rel":373},"http:\u002F\u002Fwww.cvedetails.com\u002Fvulnerability-search.php?f=1&vendor=vmware&product=esxi&cveid=&cweid=&cvssscoremin=&cvssscoremax=&psy=2012&psm=08&pey=&pem=&usy=2012&usm=08&uey=&uem=",[105],"the following address",[15,376,377],{},[378,379],"img",{"alt":380,"src":381},"","\u002Fimages\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi\u002F0ecbc06a3d.png",[15,383,384,385,387,388,391,392,395,396,202],{},"We can see that our ",[25,386,240],{},", currently in ",[25,389,390],{},"production",", has ",[25,393,394],{},"significant security holes",", so it's time to ",[25,397,398],{},"close the gaps",[10,400,402],{"id":401},"vmware-esxi-51-patches","VMware ESXi 5.1 Patches",[15,404,405,406,170,409,412,413,170,416,419,421,422,425,426,79,429,431,432,434,435,438,439,442,443,79],{},"As we saw earlier, ",[25,407,408],{},"VMware's",[25,410,411],{},"portal"," lets us ",[25,414,415],{},"download",[25,417,418],{},"patches.",[34,420],{},"\nWe'll start using this service in ",[25,423,424],{},"CLI mode"," in our ",[25,427,428],{},"ESXi busybox",[34,430],{},"\nFor my part, I'll reach my ",[25,433,99],{}," via ",[25,436,437],{},"SSH",", shut down my ",[25,440,441],{},"VMs",", and put it into ",[25,444,445],{},"maintenance",[447,448,452],"pre",{"className":449,"code":450,"language":451,"meta":380,"style":380},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","vim-cmd hostsvc\u002Fmaintenance_mode_enter\n","bash",[453,454,455],"code",{"__ignoreMap":380},[456,457,460,464],"span",{"class":458,"line":459},"line",1,[456,461,463],{"class":462},"sBMFI","vim-cmd",[456,465,467],{"class":466},"sfazB"," hostsvc\u002Fmaintenance_mode_enter\n",[15,469,470,471,473],{},"Now let's head to the ",[25,472,347],{}," to patch ESXi 5.1.",[15,475,476],{},[378,477],{"alt":380,"src":478},"\u002Fimages\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi\u002Faa6b0819d7.png",[15,480,481],{},"Now click \"Search,\" and a dropdown list appears:",[15,483,484],{},[378,485],{"alt":380,"src":486},"\u002Fimages\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi\u002Fcd07ae8da5.png",[15,488,489,490,493,494,497,498,500,501,504,505,170,508,511,512,515,516,519],{},"Here you have the last two ",[25,491,492],{},"releases"," that close vulnerabilities or ",[25,495,496],{},"bugs"," in ESXi 5.1.",[34,499],{},"\nYou need to check all the ",[25,502,503],{},"patches"," released after your version. My system's ",[25,506,507],{},"Build",[25,509,510],{},"Number"," is \"",[25,513,514],{},"799733","\" and dates from 08\u002F29\u002F2012. So I check all the available ",[25,517,518],{},"updates"," and click the \"Download now\" button.",[15,521,522,523,525],{},"Once you've downloaded the file, you have all the patches in your archive.",[34,524],{},"\nIf you run into problems, download them one by one.",[15,527,528,170,532,170,537,170,540,178,545,548,550,551,554,555,558,559,561,562,564,565,567],{},[529,530,531],"em",{},"To start, I recommend transferring them via",[529,533,534],{},[25,535,536],{},"SFTP",[529,538,539],{},"(with software like",[529,541,542],{},[25,543,544],{},"FileZilla",[529,546,547],{},"for example).",[34,549],{},"\nBe sure to note down your archive's ",[25,552,553],{},"md5sum"," in order to check its ",[25,556,557],{},"integrity"," after the transfer!",[34,560],{},"\nThe command to check the ",[25,563,553],{}," in ",[25,566,38],{}," is as follows:",[447,569,571],{"className":449,"code":570,"language":451,"meta":380,"style":380},"md5sum \u002Fpath\u002FESXi510-201406001.zip\n6f2931d6ad8d85bbc493ca42715030fb  \u002Fpath\u002FESXi510-201406001.zip\n",[453,572,573,580],{"__ignoreMap":380},[456,574,575,577],{"class":458,"line":459},[456,576,553],{"class":462},[456,578,579],{"class":466}," \u002Fpath\u002FESXi510-201406001.zip\n",[456,581,583,586],{"class":458,"line":582},2,[456,584,585],{"class":462},"6f2931d6ad8d85bbc493ca42715030fb",[456,587,588],{"class":466},"  \u002Fpath\u002FESXi510-201406001.zip\n",[15,590,591],{},"Let's check the md5 against the original source (VMware):",[447,593,595],{"className":449,"code":594,"language":451,"meta":380,"style":380},"md5sum:6f2931d6ad8d85bbc493ca42715030fb\nBuild Number: 1900470\nKB 2077640\n",[453,596,597,602,613],{"__ignoreMap":380},[456,598,599],{"class":458,"line":459},[456,600,601],{"class":462},"md5sum:6f2931d6ad8d85bbc493ca42715030fb\n",[456,603,604,606,609],{"class":458,"line":582},[456,605,507],{"class":462},[456,607,608],{"class":466}," Number:",[456,610,612],{"class":611},"sbssI"," 1900470\n",[456,614,616,619],{"class":458,"line":615},3,[456,617,618],{"class":462},"KB",[456,620,621],{"class":611}," 2077640\n",[15,623,624,625,628],{},"The ",[25,626,627],{},"MD5"," matches perfectly, let's move on to the last step.",[108,630,632],{"id":631},"patching-with-esxcli-software-vib","Patching with esxcli software vib",[15,634,635,636,638,639,642,643,646,647,649],{},"To ",[25,637,75],{}," our ",[25,640,641],{},"VMware hypervisor"," from ",[25,644,645],{},"version 5.1 to 5.1U1",", we'll use the ",[25,648,208],{}," command. Let's navigate to the following command hierarchy:",[447,651,653],{"className":449,"code":652,"language":451,"meta":380,"style":380},"esxcli software vib\n",[453,654,655],{"__ignoreMap":380},[456,656,657,659,662],{"class":458,"line":459},[456,658,208],{"class":462},[456,660,661],{"class":466}," software",[456,663,664],{"class":466}," vib\n",[15,666,667],{},"Which gives us the available commands:",[447,669,671],{"className":449,"code":670,"language":451,"meta":380,"style":380}," Available Commands:\n  get                   Displays detailed information about one or more installed VIBs\n  install               Installs VIB packages from a URL or depot. VIBs may be installed, upgraded, or\n                        downgraded. WARNING: If your installation requires a reboot, you need to disable HA\n                        first.\n  list                  Lists the installed VIB packages\n  remove                Removes VIB packages from the host. WARNING: If your installation requires a reboot, you\n                        need to disable HA first.\n  update                Update installed VIBs to newer VIB packages. No new VIBs will be installed, only updates.\n                        WARNING: If your installation requires a reboot, you need to disable HA first.\n",[453,672,673,681,713,759,800,806,825,862,878,922],{"__ignoreMap":380},[456,674,675,678],{"class":458,"line":459},[456,676,677],{"class":462}," Available",[456,679,680],{"class":466}," Commands:\n",[456,682,683,686,689,692,695,698,701,704,707,710],{"class":458,"line":582},[456,684,685],{"class":462},"  get",[456,687,688],{"class":466},"                   Displays",[456,690,691],{"class":466}," detailed",[456,693,694],{"class":466}," information",[456,696,697],{"class":466}," about",[456,699,700],{"class":466}," one",[456,702,703],{"class":466}," or",[456,705,706],{"class":466}," more",[456,708,709],{"class":466}," installed",[456,711,712],{"class":466}," VIBs\n",[456,714,715,718,721,724,727,730,733,736,738,741,744,747,750,753,756],{"class":458,"line":615},[456,716,717],{"class":462},"  install",[456,719,720],{"class":466},"               Installs",[456,722,723],{"class":466}," VIB",[456,725,726],{"class":466}," packages",[456,728,729],{"class":466}," from",[456,731,732],{"class":466}," a",[456,734,735],{"class":466}," URL",[456,737,703],{"class":466},[456,739,740],{"class":466}," depot.",[456,742,743],{"class":466}," VIBs",[456,745,746],{"class":466}," may",[456,748,749],{"class":466}," be",[456,751,752],{"class":466}," installed,",[456,754,755],{"class":466}," upgraded,",[456,757,758],{"class":466}," or\n",[456,760,762,765,768,771,774,777,780,782,785,788,791,794,797],{"class":458,"line":761},4,[456,763,764],{"class":462},"                        downgraded.",[456,766,767],{"class":466}," WARNING:",[456,769,770],{"class":466}," If",[456,772,773],{"class":466}," your",[456,775,776],{"class":466}," installation",[456,778,779],{"class":466}," requires",[456,781,732],{"class":466},[456,783,784],{"class":466}," reboot,",[456,786,787],{"class":466}," you",[456,789,790],{"class":466}," need",[456,792,793],{"class":466}," to",[456,795,796],{"class":466}," disable",[456,798,799],{"class":466}," HA\n",[456,801,803],{"class":458,"line":802},5,[456,804,805],{"class":462},"                        first.\n",[456,807,809,812,815,818,820,822],{"class":458,"line":808},6,[456,810,811],{"class":462},"  list",[456,813,814],{"class":466},"                  Lists",[456,816,817],{"class":466}," the",[456,819,709],{"class":466},[456,821,723],{"class":466},[456,823,824],{"class":466}," packages\n",[456,826,828,831,834,836,838,840,842,845,847,849,851,853,855,857,859],{"class":458,"line":827},7,[456,829,830],{"class":462},"  remove",[456,832,833],{"class":466},"                Removes",[456,835,723],{"class":466},[456,837,726],{"class":466},[456,839,729],{"class":466},[456,841,817],{"class":466},[456,843,844],{"class":466}," host.",[456,846,767],{"class":466},[456,848,770],{"class":466},[456,850,773],{"class":466},[456,852,776],{"class":466},[456,854,779],{"class":466},[456,856,732],{"class":466},[456,858,784],{"class":466},[456,860,861],{"class":466}," you\n",[456,863,865,868,870,872,875],{"class":458,"line":864},8,[456,866,867],{"class":462},"                        need",[456,869,793],{"class":466},[456,871,796],{"class":466},[456,873,874],{"class":466}," HA",[456,876,877],{"class":466}," first.\n",[456,879,881,884,887,889,891,893,896,898,901,904,907,909,912,914,916,919],{"class":458,"line":880},9,[456,882,883],{"class":462},"  update",[456,885,886],{"class":466},"                Update",[456,888,709],{"class":466},[456,890,743],{"class":466},[456,892,793],{"class":466},[456,894,895],{"class":466}," newer",[456,897,723],{"class":466},[456,899,900],{"class":466}," packages.",[456,902,903],{"class":466}," No",[456,905,906],{"class":466}," new",[456,908,743],{"class":466},[456,910,911],{"class":466}," will",[456,913,749],{"class":466},[456,915,752],{"class":466},[456,917,918],{"class":466}," only",[456,920,921],{"class":466}," updates.\n",[456,923,925,928,930,932,934,936,938,940,942,944,946,948,950],{"class":458,"line":924},10,[456,926,927],{"class":462},"                        WARNING:",[456,929,770],{"class":466},[456,931,773],{"class":466},[456,933,776],{"class":466},[456,935,779],{"class":466},[456,937,732],{"class":466},[456,939,784],{"class":466},[456,941,787],{"class":466},[456,943,790],{"class":466},[456,945,793],{"class":466},[456,947,796],{"class":466},[456,949,874],{"class":466},[456,951,877],{"class":466},[15,953,954],{},"The command details are very well explained, in my case I use the update option.",[15,956,957,960],{},[25,958,959],{},"Checking the ESXi version"," (optional):",[15,962,963],{},"Before getting started, you can check your hypervisor's version at any time:",[447,965,967],{"className":449,"code":966,"language":451,"meta":380,"style":380},"esxcli system version get\n",[453,968,969],{"__ignoreMap":380},[456,970,971,973,976,979],{"class":458,"line":459},[456,972,208],{"class":462},[456,974,975],{"class":466}," system",[456,977,978],{"class":466}," version",[456,980,981],{"class":466}," get\n",[447,983,985],{"className":449,"code":984,"language":451,"meta":380,"style":380},"Product: VMware ESXi\nVersion: 5.1.0\nBuild: Releasebuild-799733\nUpdate: 0\n",[453,986,987,998,1006,1014],{"__ignoreMap":380},[456,988,989,992,995],{"class":458,"line":459},[456,990,991],{"class":462},"Product:",[456,993,994],{"class":466}," VMware",[456,996,997],{"class":466}," ESXi\n",[456,999,1000,1003],{"class":458,"line":582},[456,1001,1002],{"class":462},"Version:",[456,1004,1005],{"class":611}," 5.1.0\n",[456,1007,1008,1011],{"class":458,"line":615},[456,1009,1010],{"class":462},"Build:",[456,1012,1013],{"class":466}," Releasebuild-799733\n",[456,1015,1016,1019],{"class":458,"line":761},[456,1017,1018],{"class":462},"Update:",[456,1020,1021],{"class":611}," 0\n",[15,1023,1024],{},"There's an equivalent to the above command, such as:",[447,1026,1028],{"className":449,"code":1027,"language":451,"meta":380,"style":380},"vmware -l\nVMware ESXi 5.1.0 Update 0\n",[453,1029,1030,1038],{"__ignoreMap":380},[456,1031,1032,1035],{"class":458,"line":459},[456,1033,1034],{"class":462},"vmware",[456,1036,1037],{"class":466}," -l\n",[456,1039,1040,1042,1045,1048,1051],{"class":458,"line":582},[456,1041,334],{"class":462},[456,1043,1044],{"class":466}," ESXi",[456,1046,1047],{"class":611}," 5.1.0",[456,1049,1050],{"class":466}," Update",[456,1052,1021],{"class":611},[15,1054,1055,1056,1059,1060,1062,1063,1066,1067,1070,1071,1073],{},"We can now ",[25,1057,1058],{},"apply"," our first ",[25,1061,75],{},"! As a first command, I recommend using the following parameter: ",[25,1064,1065],{},"--dry-run",", since it lets you know what changes will take effect after the ",[25,1068,1069],{},"update."," It's very handy to make sure you're not removing a custom ",[25,1072,177],{},", like a network card driver for example.",[15,1075,1076,1077,1079,1080,1083],{},"Here's how to apply a ",[25,1078,75],{}," in simulation mode with the ",[25,1081,1082],{},"--dry-run argument"," at the end:",[447,1085,1087],{"className":449,"code":1086,"language":451,"meta":380,"style":380},"esxcli software vib update -d \"\u002Fvmfs\u002Fvolumes\u002Fdatastore1\u002FESXi550-201407001.zip\" --dry-run\n",[453,1088,1089],{"__ignoreMap":380},[456,1090,1091,1093,1095,1098,1101,1104,1108,1111,1114],{"class":458,"line":459},[456,1092,208],{"class":462},[456,1094,661],{"class":466},[456,1096,1097],{"class":466}," vib",[456,1099,1100],{"class":466}," update",[456,1102,1103],{"class":466}," -d",[456,1105,1107],{"class":1106},"sMK4o"," \"",[456,1109,1110],{"class":466},"\u002Fvmfs\u002Fvolumes\u002Fdatastore1\u002FESXi550-201407001.zip",[456,1112,1113],{"class":1106},"\"",[456,1115,1116],{"class":466}," --dry-run\n",[447,1118,1123],{"className":1119,"code":1121,"language":1122},[1120],"language-text","Dryrun only, host not changed. The following installers will be applied\n","text",[453,1124,1121],{"__ignoreMap":380},[15,1126,1127,1128,178,1131,1134,1135,1138,1139,638,1142,1144],{},"I won't show the full list, but there are 3 categories: ",[25,1129,1130],{},"update",[25,1132,1133],{},"remove",", and ",[25,1136,1137],{},"skip",", if everything looks right to you, we can move on to ",[25,1140,1141],{},"updating",[25,1143,99],{},":",[447,1146,1148],{"className":449,"code":1147,"language":451,"meta":380,"style":380},"esxcli software vib update -d \"\u002Fvmfs\u002Fvolumes\u002Fdatastore1\u002FESXi550-201407001.zip\"\n",[453,1149,1150],{"__ignoreMap":380},[456,1151,1152,1154,1156,1158,1160,1162,1164,1166],{"class":458,"line":459},[456,1153,208],{"class":462},[456,1155,661],{"class":466},[456,1157,1097],{"class":466},[456,1159,1100],{"class":466},[456,1161,1103],{"class":466},[456,1163,1107],{"class":1106},[456,1165,1110],{"class":466},[456,1167,1168],{"class":1106},"\"\n",[15,1170,1171,1172,1175],{},"You can now ",[25,1173,1174],{},"disable maintenance mode"," on the server:",[447,1177,1179],{"className":449,"code":1178,"language":451,"meta":380,"style":380},"vim-cmd hostsvc\u002Fmaintenance_mode_exit\n",[453,1180,1181],{"__ignoreMap":380},[456,1182,1183,1185],{"class":458,"line":459},[456,1184,463],{"class":462},[456,1186,1187],{"class":466}," hostsvc\u002Fmaintenance_mode_exit\n",[15,1189,1190,76,1193,1144],{},[25,1191,1192],{},"Reboot",[25,1194,1195],{},"server",[447,1197,1199],{"className":449,"code":1198,"language":451,"meta":380,"style":380},"reboot\n",[453,1200,1201],{"__ignoreMap":380},[456,1202,1203],{"class":458,"line":459},[456,1204,1198],{"class":462},[15,1206,1207,1208,1211,1212,79,1215,1217,1218,1220,1221,1144],{},"Once the server has finished rebooting, your ",[25,1209,1210],{},"vSphere client"," will ",[25,1213,1214],{},"update itself",[34,1216],{},"\nOnce connected to the hypervisor via ",[25,1219,437],{},", here's the new update ",[25,1222,1223],{},"build",[447,1225,1226],{"className":449,"code":966,"language":451,"meta":380,"style":380},[453,1227,1228],{"__ignoreMap":380},[456,1229,1230,1232,1234,1236],{"class":458,"line":459},[456,1231,208],{"class":462},[456,1233,975],{"class":466},[456,1235,978],{"class":466},[456,1237,981],{"class":466},[447,1239,1241],{"className":449,"code":1240,"language":451,"meta":380,"style":380},"Product: VMware ESXi\nVersion: 5.1.0\nBuild: Releasebuild-1065491\nUpdate: 1\n",[453,1242,1243,1251,1257,1264],{"__ignoreMap":380},[456,1244,1245,1247,1249],{"class":458,"line":459},[456,1246,991],{"class":462},[456,1248,994],{"class":466},[456,1250,997],{"class":466},[456,1252,1253,1255],{"class":458,"line":582},[456,1254,1002],{"class":462},[456,1256,1005],{"class":611},[456,1258,1259,1261],{"class":458,"line":615},[456,1260,1010],{"class":462},[456,1262,1263],{"class":466}," Releasebuild-1065491\n",[456,1265,1266,1268],{"class":458,"line":761},[456,1267,1018],{"class":462},[456,1269,1270],{"class":611}," 1\n",[15,1272,1273,1274,1277],{},"Just repeat the same steps to move to ",[25,1275,1276],{},"5.1U2",", which gives, once applied:",[447,1279,1280],{"className":449,"code":966,"language":451,"meta":380,"style":380},[453,1281,1282],{"__ignoreMap":380},[456,1283,1284,1286,1288,1290],{"class":458,"line":459},[456,1285,208],{"class":462},[456,1287,975],{"class":466},[456,1289,978],{"class":466},[456,1291,981],{"class":466},[447,1293,1295],{"className":449,"code":1294,"language":451,"meta":380,"style":380},"Product: VMware ESXi\nVersion: 5.1.0\nBuild: Releasebuild-1483097\nUpdate: 2\n",[453,1296,1297,1305,1311,1318],{"__ignoreMap":380},[456,1298,1299,1301,1303],{"class":458,"line":459},[456,1300,991],{"class":462},[456,1302,994],{"class":466},[456,1304,997],{"class":466},[456,1306,1307,1309],{"class":458,"line":582},[456,1308,1002],{"class":462},[456,1310,1005],{"class":611},[456,1312,1313,1315],{"class":458,"line":615},[456,1314,1010],{"class":462},[456,1316,1317],{"class":466}," Releasebuild-1483097\n",[456,1319,1320,1322],{"class":458,"line":761},[456,1321,1018],{"class":462},[456,1323,1324],{"class":611}," 2\n",[15,1326,1327,1330,1332,170,1335,170,1342,170,1349],{},[529,1328,1329],{},"I'll admit the process is fairly tedious, this is a method for a single host.",[34,1331],{},[529,1333,1334],{},"There's a simpler method with",[101,1336,1339],{"href":1337,"rel":1338},"http:\u002F\u002Fwww.youtube.com\u002Fwatch?v=PF3mo3Z3mI4",[105],[529,1340,1341],{},"VMware vCenter",[101,1343,1346],{"href":1344,"rel":1345},"https:\u002F\u002F\u002F\u002Fwww.kassianoff.fr\u002F",[105],[529,1347,1348],{},"Update Manager",[529,1350,1351],{},"(paid).",[15,1353,1354,1355,1358,1359,202,1362,1364,1365,1367,1368,202],{},"You now know how to ",[25,1356,1357],{},"close a hole"," in your ",[25,1360,1361],{},"ESXi hypervisor",[34,1363],{},"\nI encourage you to close ",[25,1366,31],{},", stay informed, subscribe to the ",[25,1369,1370],{},"CVE RSS feed",[10,1372,1374],{"id":1373},"conclusion","Conclusion",[15,1376,1377],{},"This article showed how to identify and apply security patches to a VMware ESXi 5.1 hypervisor, relying on public CVE databases and VMware's patch portal, then using the esxcli software vib update command (with the --dry-run option to validate changes before applying them). This approach, while tedious on a standalone host, lets you close known vulnerabilities and reduce the infrastructure's attack surface. For larger-scale management, VMware vCenter Update Manager remains a more suitable, paid alternative.",[1379,1380,1381],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sbssI, html code.shiki .sbssI{--shiki-light:#F76D47;--shiki-default:#F78C6C;--shiki-dark:#F78C6C}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}",{"title":380,"searchDepth":582,"depth":582,"links":1383},[1384,1385,1390,1393],{"id":12,"depth":582,"text":13},{"id":20,"depth":582,"text":21,"children":1386},[1387,1388,1389],{"id":110,"depth":615,"text":111},{"id":230,"depth":615,"text":231},{"id":305,"depth":615,"text":306},{"id":401,"depth":582,"text":402,"children":1391},[1392],{"id":631,"depth":615,"text":632},{"id":1373,"depth":582,"text":1374},null,"\u002Fimages\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi\u002Fd8c6089e77.png",true,"2014-07-15","Easily update different versions of ESXi 5.x. Close a security hole in ESXi with VIBs.","md",{},"\u002Fen\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi",{"title":5,"description":1398},"patchs-securite-mises-jour-sous-vmware-esxi","en\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi","qpuyHMw637_5lOV056mUunlRlX5w21x9XwYx0nggcRg",[1407,1415,1422,1430,1436,1443,1450,1457],{"title":1408,"path":1409,"stem":1410,"date":1411,"cover":1412,"categories":1413,"children":-1},"Configuring VLANs with Junos","\u002Fen\u002Fblog\u002Fconfiguration-vlan-avec-junos","en\u002Fblog\u002Fconfiguration-vlan-avec-junos","2014-11-18","\u002Fimages\u002Fblog\u002Fconfiguration-vlan-avec-junos\u002F1b4814003c.jpg",[1414],"Réseau",{"title":1416,"path":1417,"stem":1418,"date":1419,"cover":1420,"categories":1421,"children":-1},"Basic Configuration under Junos","\u002Fen\u002Fblog\u002Fconfiguration-base-sous-junos","en\u002Fblog\u002Fconfiguration-base-sous-junos","2014-09-10","\u002Fimages\u002Fblog\u002Fconfiguration-base-sous-junos\u002F1b4814003c.jpg",[1414],{"title":1423,"path":1424,"stem":1425,"date":1426,"cover":1427,"categories":1428,"children":-1},"My Feedback on Training at Greta-Viva5 in Valence: Work-Study, the Start of the Year, the Classes","\u002Fen\u002Fblog\u002Fle-temoignage-formation-greta-viva5-valence-alternance-rentree-les-cours","en\u002Fblog\u002Fle-temoignage-formation-greta-viva5-valence-alternance-rentree-les-cours","2014-09-01","\u002Fimages\u002Fblog\u002Fle-temoignage-formation-greta-viva5-valence-alternance-rentree-les-cours\u002Fe27f7627f8.jpg",[1429],"Évènement",{"title":1431,"path":1432,"stem":1433,"date":1434,"cover":1435,"categories":1394,"children":-1},"Installing a Gandi SSL Certificate with Pound","\u002Fen\u002Fblog\u002Finstallation-certificat-ssl-gandi-avec-pound","en\u002Fblog\u002Finstallation-certificat-ssl-gandi-avec-pound","2014-08-12","\u002Fimages\u002Fblog\u002Finstallation-certificat-ssl-gandi-avec-pound\u002Fec4618d7ad.jpg",{"title":1437,"path":1438,"stem":1439,"date":1440,"cover":1441,"categories":1442,"children":-1},"Migrating from Vyatta 6.6R1 to VyOS Hydrogen","\u002Fen\u002Fblog\u002Fmigration-vyatta-6r1-vers-vyos-hydrogen","en\u002Fblog\u002Fmigration-vyatta-6r1-vers-vyos-hydrogen","2014-07-14","\u002Fimages\u002Fblog\u002Fmigration-vyatta-6r1-vers-vyos-hydrogen\u002F8a3fd53886.png",[1414],{"title":1444,"path":1445,"stem":1446,"date":1447,"cover":1448,"categories":1449,"children":-1},"Configuring an SRX100 Gateway via J-Web","\u002Fen\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web","en\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web","2014-07-10","\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002F1b4814003c.jpg",[1414],{"title":1451,"path":1452,"stem":1453,"date":1454,"cover":1455,"categories":1456,"children":-1},"Hack In Paris and Nuit du Hack, June 26-29, 2014","\u002Fen\u002Fblog\u002Fhack-paris-nuit-hack-juin-2014","en\u002Fblog\u002Fhack-paris-nuit-hack-juin-2014","2014-04-11","\u002Fimages\u002Fblog\u002Fhack-paris-nuit-hack-juin-2014\u002Fd1c6cbea4e.jpg",[1429],{"title":1458,"path":1459,"stem":1460,"date":1461,"cover":1462,"categories":1394,"children":-1},"Configuring ruTorrent's Web Interface with Apache2","\u002Fen\u002Fblog\u002Fconfigurer-interface-web-rutorrent-avec-apache2","en\u002Fblog\u002Fconfigurer-interface-web-rutorrent-avec-apache2","2014-03-31","\u002Fimages\u002Fblog\u002Fconfigurer-interface-web-rutorrent-avec-apache2\u002F672919258b.png",[],1786644890770]