Windows 8.1, Windows 7 ESU support ends
Microsoft ended support for Windows 8.1, Windows 7 ESU, and Windows Server 2008/2008 R2 ESU on Jan 10 2023, leaving unpatched systems exposed.
IPA warns that as of January 10, 2023 (US time), Microsoft ended support for Windows 8.1, Windows 7 ESU, Windows Server 2008 ESU, and Windows Server 2008 R2 ESU. After end-of-support, these products will no longer receive security updates, meaning any newly discovered vulnerabilities will remain unpatched, increasing the risk of information leakage and service disruption from exploitation.
The advisory cites historical data showing that roughly 20% of vulnerabilities found in these OSes between July 2021 and June 2022 were rated at the highest severity level (Level III), including CVE-2021-34527 (PrintNightmare), CVE-2021-34448, CVE-2021-33771, and CVE-2021-31979, all of which have confirmed exploitation in the wild — with PrintNightmare notably used to deploy ransomware. IPA also notes that third-party software (browsers, email clients) running on these unsupported OSes will progressively lose vendor support as well, compounding the risk.
IPA urges organizations still running these end-of-life operating systems to migrate promptly to supported successor or alternative products, and to update third-party applications in parallel, as continued use without vendor patching creates unmanageable and escalating security exposure.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/win8_1_eos.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free