CIS CYBER SECURITY ADVISORIES

MS-ISAC CYBER SECURITY ADVISORY NUMBER:
2013-042

DATE(S) ISSUED:
04/23/13

SUBJECT:
Support for Windows XP and Office 2003 Ending April 8, 2014

OVERVIEW:

This advisory is a reminder that Microsoft Windows XP (including all Service Packs) and Microsoft Office 2003 will reach the end of their product life cycles on April 8, 2014. As a result, Microsoft will no longer provide security updates, hot fixes, or technical support for these products.

SYSTEMS AFFECTED:

  • Microsoft Windows XP (All versions)
  • Microsoft Office 2003 (All versions)

RISK:

Government:

  • Small government entities: High
  • Large and medium government entities: High

Businesses:

  • Large and medium business entities: High
  • Small business entities: High

Home users: High

RECOMMENDATIONS:

Since these systems will no longer be supported after April 8, 2014, they represent a significant security risk to organizations using them. We recommend organizations inventory their systems to determine if the products noted above are still in use. Organizations should then develop proper migration plans to upgrade the operating systems and applications to supported products such as Windows 7 or Windows 8 and Office 2007 or 2010 as soon as possible.

It should be noted that the failure to properly upgrade end-of-lifed systems in a timely manner would subject the organization to a higher level of risk, thus increasing the potential for compromise and significant damage.

REFERENCES:

http://www.microsoft.com/en-us/windows/endofsupport.aspx