Symbol of the Government of Canada

Common menu bar links | Liens de navigation communs

Cyber Security Awareness: Windows XP SP2 End of Product Life

Number: IN10-002
Date: 20 July 2010

Purpose

The purpose of this information note is to remind existing Microsoft XP SP2 users of the product end of life, effective July 13, 2010 and provide upgrade considerations when patching to Windows XP SP3.

Assessment

As of July 13, 2010, Microsoft will no longer be supporting Windows XP SP2. All existing users are required to upgrade existing deployments to Windows XP SP3 as soon as feasible. CCIRC would like to draw user attention to the requirement for reapplying certain previously applied hotfixes and patches which, as confirmed by Microsoft, are rendered ineffective post SP3 upgrade.  Specifically, given the prevalence of Conficker, users are reminded to ensure that MS08-067 reapplication remains a high priority as part of this effort.  All users requiring SP3 upgrades are encouraged to consult with Microsoft resources for a complete list of affected hotfixes requiring reapplication.

Note:    Windows XP SP3 end of life is currently scheduled for April 2014.

Impact

No further support will be provided for Windows XP SP2, leaving systems vulnerable to future disclosed vulnerabilities and exploits.

Suggested Action

CCIRC recommends that departments take all necessary steps to upgrade affected systems to SP3 and reapply requisite patches, including MS08-067, as soon as possible.

References

The following websites contain additional information:

http://www.microsoft.com/technet/security/bulletin/MS08-067.mspx
http://support.microsoft.com/kb/958644
http://www.confickerworkinggroup.org/wiki/
http://support.microsoft.com/ph/1173#tab0

Note to Readers

The Canadian Cyber Incident Response Centre (CCIRC) provides a focal point for Canada's cyber threat and vulnerability warning, analysis and response. CCIRC is responsible for assuring the resilience of national critical infrastructure through monitoring threats and coordinating a federal response to cyber security incidents of national interest. CCIRC operates in conjunction with the Government Operations Centre (GOC) within Public Safety Canada and is a key component of the government's all-hazards approach to emergency management and national security.

For general information, please contact Public Safety Canada's Public Affairs division at:

Telephone: 613-944-4875 or 1-800-830-3118
Fax: 613-998-9589
E-mail: communications@ps-sp.gc.ca