VMware ESXi 5.0
VMware ESXi 5.0
The VMware ESXi 5.0 reached end of service life on Aug 24, 2016 — VMware no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
VMware ESXi 5.0 Support Services
VMware ended support for VMware ESXi 5.0 on August 24, 2016. The final OEM release is version 5.0 Update 3g (July 2011 release). Without a support contract, your virtualisation environment risks unpatched vulnerabilities, configuration drift, and compliance gaps. Third-party support from 3rd Party Support delivers proactive monitoring, security patches, and workarounds — keeping your ESXi 5.0 hosts stable and operational. Our OEM-trained engineers provide 24/7 global coverage, and we continue to supply replacement hardware components with tiered SLA options. Your infrastructure remains supported long after the vendor’s end-of-service-life date, typically at 40–70% lower cost than an OEM contract renewal.
Planning a move off VMware ESXi? See our VMware ESXi to AWS Elastic Compute Cloud (EC2) migration service.
24/7 engineers own your VMware ESXi 5.0 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- esxi
- release
- 5.0
- product Label
- VMware ESXi
- release Label
- 5.0
- codename
- lts
- latest Version
- 5.0 Update 3g
- release Date
- 2011-07-12
- maintained
- source Url
- https://endoflife.date/esxi
Lifecycle Dates
- End of Service Life
- Aug 24, 2016
- Last OEM Support
- Aug 24, 2016
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for VMware ESXi 5.0 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for VMware ESXi 5.0?
Proactive Monitoring
We proactively monitor the health of your VMware ESXi 5.0 hosts — tracking resource utilisation, event logs, and storage connectivity. When anomalies are detected, our engineers are alerted before performance degrades, reducing unplanned downtime.
Patches & Workarounds
We support all versions of VMware ESXi 5.0, including 5.0 Update 1 through Update 3g. If your environment runs an earlier update, we can still provide patches, workarounds, and hardware maintenance as long as the base product is ESXi 5.0.
24/7 Global Engineering
Our engineers have hands-on experience with VMware ESXi 5.0 deployments and average over a decade of IT infrastructure support. They are OEM-trained and work around the clock to resolve issues, apply patches, and design workarounds specific to your configuration.
Save 40-70% vs OEM
Third-party support for VMware ESXi 5.0 typically costs 40–70% less than the OEM contract renewal. There are no hidden fees for emergency calls or parts. You pay a predictable annual fee based on your hardware and software inventory.
VMware ESXi 5.0 Support: Frequently Asked Questions
Is the VMware ESXi 5.0 still supported?
VMware ended support for the VMware ESXi 5.0 on Aug 24, 2016 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the VMware ESXi 5.0 end of service life (EOSL) date?
VMware lists the end of service life for the VMware ESXi 5.0 as Aug 24, 2016.
Can I keep using the VMware ESXi 5.0 after its EOSL date?
Yes. EOSL means VMware stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the VMware ESXi 5.0 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Can you keep supporting VMware ESXi 5.0 after VMware ended support?
We can support VMware ESXi 5.0 with software patches and workarounds, plus hardware maintenance for the underlying servers. Our services include proactive monitoring and 24/7 access to OEM-trained engineers. Because we use a generic approach to patching, we do not require vendor-specific licensing to deliver security fixes.
What response times do you offer for VMware ESXi 5.0 support?
There is no single fixed response time. We offer a range of service-level agreements (SLAs) that vary by location and price. When you contact us about VMware ESXi 5.0, we will work with you to select the SLA that matches your business needs.
Does third-party support for VMware ESXi 5.0 include security patches?
Yes. We provide ongoing security patches and workarounds for VMware ESXi 5.0, even though the product is past its end-of-service-life date. Our engineering team monitors vulnerabilities and applies available fixes to keep your environment protected.
Do you provide replacement hardware for servers running VMware ESXi 5.0?
Absolutely. We cover hardware replacement for the servers running VMware ESXi 5.0 with multiple SLA tiers. Our parts are sourced from qualified suppliers, and we handle logistics so you can maintain your existing virtualisation infrastructure.
Will I still receive official VMware updates if I switch to 3rd Party Support for VMware ESXi 5.0?
Yes, with some caveats. We patch the hypervisor and provide workarounds for known issues. However, our support does not include access to VMware’s proprietary software downloads or license portal. We operate independently.
Known Vulnerabilities Affecting VMware ESXi 5.0
27 published CVEs affect the VMware ESXi 5.0, including 18 rated critical or high severity. VMware no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2013-3658 | HIGH | 9.4 | Sep 10, 2013 | Directory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to delete arbitrary host OS files via unspecified vectors. |
| CVE-2012-3288 | HIGH | 9.3 | Jun 14, 2012 | VMware Workstation 7.x before 7.1.6 and 8.x before 8.0.4, VMware Player 3.x before 3.1.6 and 4.x before 4.0.4, VMware Fusion 4.x before 4.1.3, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow user-assisted remote attackers to execute arbitrary code on the host OS or cause a denial of service (memory corruption) on the host OS via a crafted Checkpoint file. |
| CVE-2012-2450 | HIGH | 9.0 | May 4, 2012 | VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly register SCSI devices, which allows guest OS users to cause a denial of service (invalid write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on the guest OS. |
| CVE-2012-2449 | HIGH | 9.0 | May 4, 2012 | VMware Workstation 8.x before 8.0.3, VMware Player 4.x before 4.0.3, VMware Fusion 4.x through 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 do not properly configure the virtual floppy device, which allows guest OS users to cause a denial of service (out-of-bounds write operation and VMX process crash) or possibly execute arbitrary code on the host OS by leveraging administrative privileges on the guest OS. |
| CVE-2012-1518 | HIGH | 8.3 | Apr 17, 2012 | VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS privileges via unspecified vectors. |
| CVE-2013-3519 | HIGH | 7.9 | Dec 4, 2013 | lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1, when a 32-bit Windows guest OS is used, allows guest OS users to gain guest OS privileges via an application that performs a crafted memory allocation. |
| CVE-2010-4263 | HIGH | 7.9 | Jan 18, 2011 | The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34, when Single Root I/O Virtualization (SR-IOV) and promiscuous mode are enabled but no VLANs are registered, allows remote attackers to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact via a VLAN tagged frame. |
| CVE-2016-5330 | HIGH | 7.8 | Aug 8, 2016 | Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before 8.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory. |
| CVE-2012-3289 | HIGH | 7.8 | Jun 14, 2012 | VMware Workstation 8.x before 8.0.4, VMware Player 4.x before 4.0.4, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 allow remote attackers to cause a denial of service (guest OS crash) via crafted traffic from a remote virtual device. |
| CVE-2010-3904 | HIGH | 7.8 | Dec 6, 2010 | The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls. |
| CVE-2013-1659 | HIGH | 7.6 | Feb 22, 2013 | VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data stream. |
| CVE-2023-29552 | HIGH | 7.5 | Apr 25, 2023 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor. |
| CVE-2013-3657 | HIGH | 7.5 | Sep 10, 2013 | Buffer overflow in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors. |
| CVE-2012-2448 | HIGH | 7.5 | May 4, 2012 | VMware ESXi 3.5 through 5.0 and ESX 3.5 through 4.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory overwrite) via NFS traffic. |
| CVE-2013-1406 | HIGH | 7.2 | Feb 11, 2013 | The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4 and 5.0 before 5.0.2, VMware View 4.x before 4.6.2 and 5.x before 5.1.2 on Windows, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 does not properly restrict memory allocation by control code, which allows local users to gain privileges via unspecified vectors. |
| CVE-2012-1510 | HIGH | 7.2 | Mar 16, 2012 | Buffer overflow in the WDDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges via unspecified vectors. |
| CVE-2012-1508 | HIGH | 7.2 | Mar 16, 2012 | The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors. |
| CVE-2013-5970 | HIGH | 7.1 | Oct 21, 2013 | hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by modifying management traffic. |
| CVE-2022-31681 | MEDIUM | 6.5 | Oct 7, 2022 | VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host. |
| CVE-2014-8370 | MEDIUM | 6.4 | Jan 29, 2015 | VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS users to gain host OS privileges or cause a denial of service (arbitrary write to a file) by modifying a configuration file. |
Showing the 20 most severe of 27 known CVEs.
Get Third Party Support