Upgrading to XP SP3 and beyond

Share this article:
Dan Kaplan, executive editor, SC Magazine
Dan Kaplan, executive editor, SC Magazine

The death of Windows XP Service Pack (SP) 2 is set for this month, but many IT administrators appear to be in denial.

July 13 is the date Microsoft has pledged to cease support for the operating system update. SP2 was released in 2006, with SP3 following two years later. Yet, many organizations, citing its reliability and stability, still are running SP2, said Wolfgang Kandek, CTO of vulnerability management firm Qualys.

That, however, may invite security risks, given that Microsoft will stop releasing monthly patches for SP2, Kandek said.

“The danger is that, within a couple of months, SP 2 will have vulnerabilities that officially don't exist, but attackers will know they exist,” Kandek said.

About a year ago, Qualys began tracking XP SP2 migrations across roughly one million machines, Kandek said. The company found that at that time, 80 percent of XP computers ran the soon-to-be-unsupported service pack, though the number has dwindled to 50 percent.

Kandek said he blames Vista, oft criticized for its usability and hardware compatibility shortfalls, with the slowness for many to migrate. Vista, released in January 2007, failed to permeate businesses and the resulting flop kept many organizations in the comforts of SP2.

But as the end-of-life date now approaches for SP2, the easiest move for organizations is to upgrade to SP3, Kandek said. Installing the package is similar to updating computers with security updates. Yet, administrators should be careful to test the new service pack, Kandek advised.

In addition, research firm Gartner recommends that organizations plan and test Windows 7 this year, with the goal of eliminating XP by the end of 2012. Microsoft plans to end support for XP – and with it, the nine-year-old Internet Explorer 6 – in April 2014. (Google Reader and YouTube already have stopped supporting IE6).

“Windows 7 has been getting positive reviews, and many clients report that they have plans to start their production deployments, but there are some that are still undecided about when to start and how quickly to do the migration,” said Michael Silver, vice president and distinguished analyst at Gartner.

Organizations could opt to deploy Windows 7 all at once or gradually, Gartner said. They should work with their software providers to determine when they will provide support for the new platform.

Share this article:

Sign up to our newsletters

More in News

In Cisco probe, misuse or compromise spotted on all firms' networks

In Cisco probe, misuse or compromise spotted on ...

Cisco analyzed the business networks of 30 multinational companies last year, and revealed the findings in its 2014 Annual Security Report.

Fareit trojan observed spreading Necurs, Zbot and CryptoLocker

The Necurs and Zbot trojans, as well as CryptoLocker ransomware, has been observed by researchers as being spread through another trojan, known as Fareit.

Post Heartbleed, tech giants join initiative to bolster open source

Post Heartbleed, tech giants join initiative to bolster ...

The newly formed Core Infrastructure Initiative, created to boost under-funded open source projects, will tackle OpenSSL first.