by

Windows 10 holdouts become security bait

A stubborn rump of Windows 10 machines is turning into enterprise security chum as Microsoft’s support clock keeps ticking.

Asset tracking outfit Lansweeper says Windows 10 still runs on 16.9 per cent of Windows devices it monitors, or “roughly one in six.” A year ago, the ancient operating system sat on about half of the machines in its dataset.

That share had fallen to the low-to-mid 40 per cent range by the time Microsoft ended standard support. It kept sliding to 18.6 per cent in June, but Lansweeper says migration has now slowed to a crawl.

That leaves enterprises with a security problem that refuses to shuffle off quietly. Even systems enrolled in Microsoft’s Extended Security Updates scheme will eventually be left to fend for themselves.

Consumer devices can receive security fixes until 12 October 2027. Commercial customers prepared to pay can stretch coverage until 10 October 2028, after which the patch tap gets turned off.

Small and medium-sized businesses are especially exposed. Lansweeper reckons 21.4 per cent of SMB machines still run Windows 10, usually because upgrading costs money someone does not want to spend.

Some sectors look worse. Healthcare and pharmaceutical systems are still clinging to Windows 10 at 23 per cent, while consumer and retail machines sit at 22.7 per cent.

According to Lansweeper’s data, “a Windows 10 device carries an average of 1,903 active CVEs against 652 on Windows 11. That’s a 2.9x gap.”

Lansweeper principal technical evangelist Esben Dochy said: “The Windows 10 average also includes devices that have ESU patches applied.”

One headache is “patch diffing,” where Windows 11 fixes can be reverse-engineered to find flaws in Windows 10. “The supported OS effectively hands attackers a map into the unsupported one,” Lansweeper said.

Only 14 per cent of Windows 10 assets have ESU patches applied, according to Lansweeper’s figures. That suggests plenty of kit is not just old, but wandering about without much of a coat.

Dochy said: “I think a meaningful share of the remaining Windows 10 estate isn’t being actively unpatched by neglect. It’s being held in place by vendor dependency, certification gaps, cost, or accepted risk. Certified equipment is a good example: many medical devices and industrial systems have their OS tied directly to vendor certification, and in some cases, a Windows 11-certified version of that device or software doesn’t yet exist. The same applies in retail, where devices are often vendor-locked to specific OS versions for compliance or warranty reasons.”

 

TOPICS:
CVEs  ·  enterprise security  ·  ESU  ·  lansweeper  ·  Microsoft  ·  patch management  ·  SMBs  ·  Windows 10  ·  windows 11

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews