Windows 11 systems must be maintained at a supported servicing level.

STIG ID: WN11-00-000040  |  SRG: SRG-OS-000480-GPOS-00227 |  Severity: high (CAT I)  |  CCI: CCI-000366 |  Vulnerability Id: V-253263

Vulnerability Discussion

Windows 11 is maintained by Microsoft at servicing levels for specific periods of time to support Windows as a Service. An operating system release is considered "supported" if the vendor continues to provide security patches for the product. With an unsupported release, it will not be possible to resolve security issues discovered in the system software. Systems at unsupported servicing levels or releases will not receive security updates for new vulnerabilities which leaves them subject to exploitation.

The type of servicing channel used will determine the frequency of OS updates and length of support. Under the General Availability Channel (GAC), Microsoft releases one major feature update per year (typically in the second half of the calendar year, e.g., Version 24H2). For Windows 11 Enterprise, each annual GAC release receives 36 months of support. The Long-Term Servicing Channel (LTSC) is designed for highly regulated, air-gapped, or mission-critical military/tactical environments. Microsoft releases a new LTSC version approximately every 2 to 3 years. Windows 11 Enterprise LTSC receives five years of lifecycle support (quality and security updates only; no feature updates).

Many Microsoft software updates and fixes are regularly combined into a single package (called a service pack) that is made available for installation. Both the Mainstream Support and Extended Support phases for software require a product's supported service pack to be installed to continue to receive full support. Microsoft publishes specific support timelines for a previous service pack when the new service pack is released. Systems must install a fully supported service pack to ensure they are on the latest and most secure version of their product.

Check

1. Determine your Windows 11 OS version.
a. Run "winver.exe".
The "About Windows" dialog box will display the system's version and OS build. For example, "Microsoft Windows 11 Version 24H2 (OS Build 26100.8875)". Record the numbers observed.

2. Determine the system's latest installed security patch.
a. Open "PowerShell" with elevated privileges (run as administrator).
b. Enter the following:
Get-HotFix -Description "Security Update"
c. Record the "InstalledOn" date and the KB numbers listed under the "HotFixID" column in the resulting display.

3. Determine Microsoft's Support timeframe for the system's Windows 11 OS version.
a. Access Microsoft's Lifecycle & Build History website at https://learn.microsoft.com/en-us/windows/release-health/windows11-release-information.
b. Review the table listing the "Windows 11 current versions by servicing option" to find the end-of-support date corresponding to the system's OS version. This date marks the official deadline after which Microsoft stops providing software support (or security updates) for that operating system version. The Windows 11 current versions are categorized by servicing option. For example, (as of Aug 2026) under the General Availability Channel for Enterprise version 25H, the last date for (support) updates is 2028-10-10, and the latest build is 26200.9168. Similar data is provided for the Enterprise LTSC releases.
c. Review (on the same page) a table listing "Windows 11 release history" data for OS hotpatch updates. Compare the system's OS build and KB # (from step 1 and 2) with those listed to determine how many (if any) newer patches are available for the system's OS version. It is strongly recommended that the latest security patch be installed, unless there is a valid operational reason to delay installing it.

If the end-of-support date for the system's OS version (from step 3b) is a past date, this is a finding.

Fix

Determine if the end-of-support date for the system's OS build (from Microsoft's Windows 11 release history website) is a past date.
If the end-of-support date for the system's OS build is in the past, perform an update to an OS build whose end-of-support date is a future date.