Windows 10 systems must be maintained at a supported servicing level.

STIG ID: WN10-00-000040  |  SRG: SRG-OS-000480-GPOS-00227 |  Severity: high (CAT I)  |  CCI: CCI-003376 |  Vulnerability Id: V-220706

Vulnerability Discussion

Windows 10 is maintained by Microsoft at servicing levels for specific periods of time to support Windows as a Service. Systems at unsupported servicing levels or releases will not receive security updates for new vulnerabilities, which leaves them subject to exploitation.

New versions with feature updates are planned to be released on a semiannual basis with an estimated support timeframe of 18 to 30 months depending on the release. Support for previously released versions has been extended for Enterprise editions.

A separate servicing branch intended for special-purpose systems is the Long-Term Servicing Channel (LTSC, formerly Branch - LTSB), which will receive security updates for 10 years but excludes feature updates.

Check

Run "winver.exe".

If the "About Windows" dialog box does not display a version supported by the vendor, this is a finding.

Fix

Upgrade to a supported version of the operating system.