In wake of WannaCry, Microsoft fixes 3 flaws affecting unsupported OSes including Windows XP and Windows Server 2003 that it initially said it wouldn't patch
The company previously said it would not fix three outstanding exploits, but reversed course following the ransomware attack in May.
Context & Ripple Effects
Two weeks ago, Microsoft broke its own end-of-support rule with an emergency update for Windows XP, Windows 8, and Windows Server 2003 after WannaCry spread using an SMB exploit (out-of-band patches issued mid-attack). Today's move goes further: three flaws the company had explicitly declined to fix on those same unsupported systems are now patched anyway.
The reversal matters because it converts a hard policy line into a negotiable one — and the related coverage shows the line keeps getting renegotiated, from the 2019 RDS wormable-exploit warnings that again pulled XP into scope to the 2020 'wormable' flaw patch that Check Point traced to code 17 years old.
First-order effects
- Organizations still running Windows XP and Windows Server 2003 gain fixes for three known exploits they had been told would never come, extending the usable life of machines past their support cutoff.
- Microsoft's stated position that unsupported OSes receive no security patches is publicly abandoned, at least where exploitability is demonstrated.
Second-order effects
- Enterprises that had used end-of-support dates as a forcing function for upgrades now have evidence that lifelines appear under attack pressure, weakening the migration deadline argument IT departments relied on.
- Security teams and attackers alike recalibrate: unpatched legacy fleets become a predictable target class, since each high-profile outbreak has so far triggered retroactive fixes rather than none.
Third-order effects
- If the pattern holds — WannaCry in 2017, the RDS warning in 2019, the wormable-flaw patch in 2020 — Microsoft is drifting toward de facto perpetual security support for its installed base, with formal end-of-life dates functioning as marketing milestones rather than real cutoffs.
- Ransomware outbreaks emerge as the effective regulator of legacy-software policy, setting patch cadence for systems no contract obligates Microsoft to maintain.
The trend: Major ransomware events are turning Microsoft's end-of-support cutoffs into conditional ones, with legacy Windows versions repeatedly pulled back into the patching cycle after each outbreak.