US-CERT- AA19-290A: Microsoft Ending Support for Windows 7 and Windows Server 2008 R2

Started by Netwörkheäd, November 14, 2019, 12:01:37 AM

Previous topic - Next topic

Netwörkheäd

AA19-290A: Microsoft Ending Support for Windows 7 and Windows Server 2008 R2

Original release date: October 17, 2019 | Last revised: October 18, 2019<br/><h3>Summary</h3><p><em><strong>Note</strong>: This alert does not apply to federally certified voting systems running Windows 7. Microsoft will continue to provide free security updates to those systems through the 2020 election. See Microsoft's article, <a href="https://blogs.microsoft.com/on-the-issues/2019/09/20/extending-free-windows-7-security-updates-to-voting-systems/">Extending free Windows 7 security updates to voting systems</a>, for more information.</em></p>

<p>On January 14, 2020, Microsoft will end extended support for their Windows 7 and Windows Server 2008 R2 operating systems.<a href="https://www.microsoft.com/en-us/windows/windows-7-end-of-life-support-information">[1]</a> After this date, these products will no longer receive free technical support, or software and security updates.</p>

<p>Organizations that have regulatory obligations may find that they are unable to satisfy compliance requirements while running Windows 7 and Windows Server 2008 R2.</p>
<h3>Technical Details</h3><p>All software products have a lifecycle. "End of support" refers to the date when the software vendor will no longer provide automatic fixes, updates, or online technical assistance. <a href="https://support.microsoft.com/en-us/help/13853/windows-lifecycle-fact-sheet">[2]</a></p>

<p>For more information on end of support for Microsoft products see the <a href="https://www.microsoft.com/en-us/windows/windows-7-end-of-life-support-information">Microsoft End of Support FAQ</a>.</p>

<p>Systems running Windows 7 and Windows Server 2008 R2 will continue to work at their current capacity even after support ends on January 14, 2020. However, using unsupported software may increase the likelihood of malware and other security threats. Mission and business functions supported by systems running Windows 7 and Windows Server 2008 R2 could experience negative consequences resulting from unpatched vulnerabilities and software bugs. These negative consequences could include the loss of confidentiality, integrity, and availability of data, system resources, and business assets.</p>
<h3>Mitigations</h3><p>The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and organizations to:</p>

<ul>
<li>Upgrade to a newer operating system.</li>
<li>Identify affected devices to determine breadth of the problem and assess risk of not upgrading.&nbsp;</li>
<li>Establish and execute a plan to systematically migrate to currently supported operating systems or employ a cloud-based service.&nbsp;</li>
<li>Contact the operating system vendor to explore opportunities for fee-for-service maintenance, if unable to upgrade.&nbsp; &nbsp;</li>
</ul>
                    <h3>References</h3>
        <ul>             <li><a href="https://www.microsoft.com/en-us/windows/windows-7-end-of-life-support-information">[1] Microsoft End of Support FAQ</a></li>             <li><a href="https://support.microsoft.com/en-us/help/13853/windows-lifecycle-fact-sheet">[2] Microsoft Windows Lifecyle Fact Sheet</a></li>             <li><a href="https://docs.microsoft.com/en-us/windows/deployment/upgrade/windows-upgrade-and-migration-considerations">[3] Microsoft Windows Upgrade and Migration Considerations</a></li>             <li><a href="https://www.computerworld.com/article/3431616/leaving-windows-7-here-are-some-non-windows-options.html">[4] ComputerWorld: Leaving Windows 7? Here are Some non-Windows Options</a></li>             <li><a href="https://www.us-cert.gov/ncas/analysis-reports/AR19-133A">[5] CISA Analysis Report AR19-133A: Microsoft Office 365 Security Observations</a></li>         </ul>            <h3>Revisions</h3>
<ul>             <li>October 17, 2019:  Initial version</li>             <li>October 18, 2019:  Added note</li> </ul>
<hr />
            <div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p class="privacy-and-terms">This product is provided subject to this <a href="https://www.us-cert.gov/privacy/notification">Notification</a> and this <a href="https://www.dhs.gov/privacy-policy">Privacy &amp; Use</a> policy.</p>


</div>
Source: AA19-290A: Microsoft Ending Support for Windows 7 and Windows Server 2008 R2
Let's not argue. Let's network!