VMware update manager vs Microsoft updates

Posted on 2009-03-31
Last Modified: 2012-05-06
We have a series of ESX 3.5 VM's that are referenced against a dynamic VMware baseline for updates. The baseline is set to check weekly for Critical updates, another task schedules the VM scan to compare against the baseline.
With VM's remediated against the latest baseline I am seeing a larghe discrepancy between what VMware sees as required critical updates, and what microsoft feels are required critical/hi priority updates.
I understand that the updates come from different sources, but can anyone explain why they might be so vastly different?
Question by:agradmin
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
  • +1
LVL 21

Accepted Solution

za_mkh earned 400 total points
ID: 24032931
We use VMWare Update Manager, but have to say that we only use it for ESX host update management. We keep to WSUS for the MS updates. The update source VMWare Update Manager uses is by a company called Shavlik (
It could be that they are not updating as quickly as MS pushes the updates out? But as far as I know Shavlik should be deciding as to what an update's criticallity is?
LVL 20

Expert Comment

ID: 24034156
If am understanding correctly, you are comparing 2 completely different things, you can't compare these the VMware updates are the vmhost platform.  The microsoft updates are for the server running on top of of the VMhost.
LVL 42

Expert Comment

ID: 24035755
From what I've seen use VMWare Update for hosts and use WSUS for microsoft updates (it can be a VM)
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.


Author Comment

ID: 24038400
For clarification, it is the MS Vm guests that pose the problem - we do use Update manager to update the ESX hosts.
We can use WSUS to update the VM's - are others using WSUS due to preference or resulting from similar problems with updating guests with Update Manager?
What are the advantages of using WSUS? - I like the scheduling and snapshot ability built into Update Manager.
LVL 42

Assisted Solution

paulsolov earned 100 total points
ID: 24038868
We implement WSUS for Windows OS because it's designed for Windows and not a 3rd party product so we know that it will download all the updates that we need.  Just as VMWare does a good job with Updater for the host updates we usually stick to what works for each product.  
LVL 21

Assisted Solution

za_mkh earned 400 total points
ID: 24044046
At the moment, we also stick to 'best' of breed for each application, in that WSUS for MS, and VUM for ESX hosts. But the shavlik techonology is pretty interesting (since it can manage security for so many more applications) so we are actually looking at that to see if we can manage our estate via that (regardless of whether PC is physical or virtual).
But you are right, I too like the facility to snapshot VM's before applying updates, and then automatically removing them after a predefined time. I guess to answer your question, you could maybe direct it to the shavlik (who provide the MS updates) for the VUM. You could get a better answer out of them.
Good luck

Author Closing Comment

ID: 31564927
After more searching VMware/Shavlik download patches that are deemed 'Critical', where MS is downloading those rated as "Priority". The MS "Priority" patches outnumber the Vmware "Critical" hence the difference.

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If we need to check who deleted a Virtual Machine from our vCenter. Looking this task in logs can be painful and spend lot of time, so the best way to check this is in the vCenter DB. Just connect to vCenter DB(default DB should be VCDB and using…
In this article we will learn how to backup a VMware farm using Nakivo Backup & Replication. In this tutorial we will install the software on a Windows 2012 R2 Server.
Teach the user how to use configure the vCenter Server storage filters Open vSphere Web Client:  Navigate to vCenter Server Advanced Settings: Add the four vCenter Server storage filters: Review the advanced settings: Modify the values of the four v…
Teach the user how to join ESXi hosts to Active Directory domains Open vSphere Client: Join ESXi host to AD domain: Verify ESXi computer account in AD: Configure permissions for domain user in ESXi: Test domain user login to ESXi host:

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question