Legacy Operating Systems
- vulnerabilities, misconfigs, careless users are some things that even upgrading to the latest versions cannot fix
- however, in large corp envs, we do see legacy operating systems.
- Windows systems first go into an "extended support" period before being classified as end-of-life or no longer officially supported.
- DETAILED LIST: https://michaelspice.net/windows/end-of-life-microsoft-windows-and-office/


Impact

- CVE SigRed - https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-1350
- CVE EternalBlue - https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2017-0144
- we do not see many hosts running server 2000 or Windows XP workstations vulnerable to MS08-067, they exist, and I come across them on occasion.
- Be careful while attacking them as they may be running mission critical apps.
- confer with client