Purpose
Resolution
ESX is not a GP computing environment - but incorporates a semi-privileged GP environment, the Linux-based Console Operating System (COS). Antivirus and Malware Detection services are supported in this environment subject to the Third Party Software Support Policy. However, VMware does not recommend the usage of Third Party Software in the COS (as stated in the Support Policy), but recommends that best practices be employed to secure the ESX COS network interface.
ESXi is neither a GP environment, nor does it utilize a COS. ESXi provides for console functionality (for initial configuration, troubleshooting, and Technical Support) via the Direct Connect User Interface (DCUI) and Tech Support Mode. These strongly controlled interfaces provide GP-like console functionality augmented for security and trust. All binaries executed in ESXi are signed, keyed, or validated by strong controls. There is no facility to interpret code at runtime and the compiled modules are subject to both the controls for execution and a default-deny policy (for unsigned code), integral to the kernel.
Based on Regulatory Compliance, VMware believes that the customers should categorize ESX/ESXi hypervisors as they would for other network based appliances and treat them accordingly. By following the Best Practices outlined in the vSphere hardening guides, you can be reasonably assured of the security and integrity of the ESXi host's management interfaces. As VMware transitions from ESX to ESXi (and away from the general purpose OS running the COS), the need to run Antivirus/Anti Malware solutions to protect the hypervisor is even further diminished.
Based on VMware KB 1036544