{"id":1553,"date":"2024-05-22T20:54:08","date_gmt":"2024-05-23T01:54:08","guid":{"rendered":"https:\/\/zewwy.ca\/?p=1553"},"modified":"2024-05-22T20:54:08","modified_gmt":"2024-05-23T01:54:08","slug":"vmware-patches-may-2024","status":"publish","type":"post","link":"https:\/\/zewwy.ca\/index.php\/2024\/05\/22\/vmware-patches-may-2024\/","title":{"rendered":"VMware Patches May 2024"},"content":{"rendered":"<p>Yup this shit never ends:<\/p>\n<p><a href=\"https:\/\/support.broadcom.com\/web\/ecx\/support-content-notification\/-\/external\/content\/SecurityAdvisories\/0\/24308\">VMSA-2024-0011:VMware ESXi, Workstation, Fusion and vCenter Server updates address multiple security vulnerabilities<\/a><\/p>\n<h2 style=\"text-align: center;\"><span class=\"ez-toc-section\" id=\"Patching_vCenter\"><\/span>Patching vCenter<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Login to VAMI, lets see what I&#8217;m on:<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/xcRJlUK.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/xcRJlUK.png\" alt=\"\" width=\"679\" height=\"141\" \/><\/a><\/p>\n<p>Here&#8217;s the fix Matrix:<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/9nrA1nu.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/9nrA1nu.png\" alt=\"\" width=\"1244\" height=\"231\" \/><\/a><\/p>\n<p>Can you tell if I&#8217;m good, no cause the Matrix uses a different version coding (7.0 u3q) vs the version shown in VAMI (7.0.3.01700). You can either look up, by googling the version, which I did and it&#8217;s 7.0 u3o), or clicking the <a href=\"https:\/\/docs.vmware.com\/en\/VMware-vSphere\/7.0\/rn\/vsphere-vcenter-server-70u3q-release-notes\/index.html\">link in the KB and checking the build number<\/a>.<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/owRaEPA.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/owRaEPA.png\" alt=\"\" width=\"1483\" height=\"320\" \/><\/a><\/p>\n<p>VMware: constructive criticism.. make the Matrix have the same versioning syntax as VAMI so it&#8217;s easy to know, and verify.<\/p>\n<p>Anyway, in VAMI click update. there it is&#8230;.<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/DJzwbR5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/DJzwbR5.png\" alt=\"\" width=\"2256\" height=\"598\" \/><\/a><\/p>\n<p>Accept the EULA, Pass pre-update checks, Installing&#8230;<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/uHZUvDW.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/uHZUvDW.png\" alt=\"\" width=\"624\" height=\"274\" \/><\/a><\/p>\n<p><a href=\"https:\/\/i.imgur.com\/KSMGEWt.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/KSMGEWt.png\" alt=\"\" width=\"314\" height=\"636\" \/><\/a><\/p>\n<p><a href=\"https:\/\/i.imgur.com\/GjB9TDP.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/GjB9TDP.png\" alt=\"\" width=\"759\" height=\"986\" \/><\/a><\/p>\n<p>It&#8217;s chugging along&#8230;<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/uinjwcI.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/uinjwcI.png\" alt=\"\" width=\"615\" height=\"273\" \/><\/a><\/p>\n<p>at this point the vCenter regular web interface was unresponsive, and had to use the host that was running the VCSA to get the CPU usage. However, as you can see VAMI appears to be up and showing status just fine.<\/p>\n<p>45 Minutes later&#8230;<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/ceMjMsQ.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/ceMjMsQ.png\" alt=\"\" width=\"1057\" height=\"335\" \/><\/a><\/p>\n<p><a href=\"https:\/\/i.imgur.com\/oDWzE4R.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/oDWzE4R.png\" alt=\"\" width=\"599\" height=\"256\" \/><\/a><\/p>\n<p>alright&#8230; 1% woo, woo, woo! Why does this seem oddly familiar&#8230;. mhmm anyway. After about an hour&#8230;<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/RSyhEKq.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/RSyhEKq.png\" alt=\"\" width=\"604\" height=\"262\" \/><\/a><\/p>\n<p>Re-log into VAMI.<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/RnISHAh.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/RnISHAh.png\" alt=\"\" width=\"1940\" height=\"556\" \/><\/a><\/p>\n<p>Looks good, going to the main mgmt page&#8230; mhmm shows 404, but by the time I wanted to get a snip, it refreshed to show the FBA page, so I logged in like normal.<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/Ajd9Zcf.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/Ajd9Zcf.png\" alt=\"\" width=\"1728\" height=\"1032\" \/><\/a><\/p>\n<p>Yay it worked.<\/p>\n<h2 style=\"text-align: center;\"><span class=\"ez-toc-section\" id=\"Patching_ESXi\"><\/span>Patching ESXi<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>In vCenter, go to the host, pick updates, then baseline, and check compliance.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i.imgur.com\/FL5Vo0R.png\" \/><\/p>\n<p>On the two baselines, select them and pick remediate.<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/5QZoxHf.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/5QZoxHf.png\" alt=\"\" width=\"1145\" height=\"949\" \/><\/a><\/p>\n<p>Server went into maintenance mode, and after about 20 min (I think it rebooted, I didn&#8217;t have an active ping on it, not sure will check on the next one).<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/8b9Glg6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/8b9Glg6.png\" alt=\"\" width=\"1728\" height=\"839\" \/><\/a><\/p>\n<p>My PA-ESXi is a special beast, it for some reason needs a helping hand during boot, so we&#8217;ll know if it reboots this time&#8230;<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/URFUSSb.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/URFUSSb.png\" alt=\"\" width=\"1734\" height=\"826\" \/><\/a><\/p>\n<p>yup&#8230; it rebooted.<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/0VDxUig.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/0VDxUig.png\" alt=\"\" width=\"495\" height=\"106\" \/><\/a><\/p>\n<p>Fun times had by all.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Yup this shit never ends: VMSA-2024-0011:VMware ESXi, Workstation, Fusion and vCenter Server updates address multiple security vulnerabilities Patching vCenter Login to VAMI, lets see what I&#8217;m on: Here&#8217;s the fix Matrix: Can you tell if I&#8217;m good, no cause the Matrix uses a different version coding (7.0 u3q) vs the version shown in VAMI (7.0.3.01700). &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/zewwy.ca\/index.php\/2024\/05\/22\/vmware-patches-may-2024\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;VMware Patches May 2024&#8221;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"sfsi_plus_gutenberg_text_before_share":"","sfsi_plus_gutenberg_show_text_before_share":"","sfsi_plus_gutenberg_icon_type":"","sfsi_plus_gutenberg_icon_alignemt":"","sfsi_plus_gutenburg_max_per_row":"","footnotes":""},"categories":[5,8],"tags":[463,88],"class_list":["post-1553","post","type-post","status-publish","format-standard","hentry","category-hypervisors","category-server-administration","tag-patching","tag-vmware"],"_links":{"self":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/1553","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/comments?post=1553"}],"version-history":[{"count":1,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/1553\/revisions"}],"predecessor-version":[{"id":1556,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/1553\/revisions\/1556"}],"wp:attachment":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/media?parent=1553"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/categories?post=1553"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/tags?post=1553"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}