Windows Server 2022 must be maintained at a supported servicing level.

STIG ID: WN22-00-000100  |  SRG: SRG-OS-000480-GPOS-00227 |  Severity: medium (CAT II)  |  CCI: CCI-000366 |  Vulnerability Id: V-254247

Vulnerability Discussion

Systems at unsupported servicing levels will not receive security updates for new vulnerabilities, which leave them subject to exploitation. Systems must be maintained at a servicing level supported by the vendor with new security updates. For Windows Server 2022, Microsoft made the following statement at https://support.microsoft.com/en-us/servicing/os/windows-server/2026/08/kb5120242-windows-server-2022-security-update regarding ongoing OS support:

"On October 13, 2026, Windows Server 2022 will reach end of mainstream support. The October 2026 security update will be the last mainstream support update available for this version. After this date, Windows Server 2022 will transition to extended support, which includes security updates at no additional cost, and will continue to receive monthly security updates through October 14, 2031."

The Long-Term Servicing Channel (LTSC) remains the standard support branch for Enterprise server platforms. The guidance in this rule assumes usage via this support channel.

Check

1. Determine the system's OS version:
a. Open "Command Prompt".
b. Run "winver.exe". The "About Windows" dialog box will display the system’s version and OS build. For example, "Microsoft Windows Server Version 21H2 (Build 20348.5499)".
c. Record the numbers for the system.

2. Determine Microsoft's support stance for Windows 2022:
As of this writing, the published guidance (at https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2022) states that Mainstream Support ends on 10/14/2026 and Extended Support ends on 10/15/2031. Visit the site to determine the latest support date guidance.

3. Determine Microsoft's latest available Windows 2022 OS version and Security Patch:
a. Access Microsoft’s Lifecycle & Build History website at https://learn.microsoft.com/en-us/windows/release-health/windows-server-release-info.
b. Review the Windows 2022 table (under heading of "Windows Server release history"). To view the table, expand heading of "Windows Server 2022 (OS build 20348)".
c. Compare the system’s OS build and KB # with those listed to determine how many (if any) newer patches are available for the system’s OS version. It is strongly recommended that the latest security patch be installed, unless there is a valid operational reason to delay installing it.

If the end-of-support date (which includes the "Extended End Date") for the system’s OS version is a past date, this is a finding.

Note: Preview versions must not be used in a production environment.

Fix

Ensure the system is at Version 21H2 (Build 20348.xxx) or greater.
Determine if the end-of-support date for the system’s OS build is a past date.
If the end-of-support date for the system’s OS build is in the past, perform an update to an OS build whose end-of-support date is a future date.