Microsoft has warned that PCs running unsupported versions of Windows will silently stop receiving security updates after the next Windows Update certificate rotation, a cut-off the company has framed as cryptographic rather than administrative — a hard break in the signing chain, not a gradual degradation of service.
According to BleepingComputer, the mechanism is cryptographic in the strictest sense: Windows Update signs its updates using certificates that rely on the SHA-2 algorithm. Machines that cannot verify SHA-2 code signatures will be unable to trust the new signing chain once the rotation occurs, and will simply stop being offered updates — with no visible error message and nothing in typical monitoring to flag the failure. For administrators, the practical effect is that an inventory-verified device can quietly fall out of the patching perimeter, appear healthy in dashboards, and accumulate unpatched vulnerabilities indefinitely.
Affected platforms
The versions Microsoft identified as lacking the required SHA-2 support — and therefore set to lose update delivery at the rotation — are:
| Product | Support status |
|---|---|
| Windows Vista (all editions) | Long out of support |
| Windows 7 RTM (no Service Pack 1) | Superseded by SP1 |
| Windows 8 RTM (no Update) | Superseded by Windows 8.1 Update |
| Windows Server 2003 / 2003 R2 | Long out of support |
| Windows Server 2008 RTM (no SP) | Superseded by SP2 |
| Windows XP Embedded / POSReady | Extended support expired |
Devices running Windows 7 SP1, Windows 8.1 Update, and their server equivalents remain eligible provided they have the SHA-2 update stack installed — Microsoft has published a servicing-stack update that backports SHA-2 signature verification to these platforms.
The 延長安全更新 (ESU) bridge
For Windows 10 — which reached end-of-life on 14 October 2025 — the only sanctioned route to continued patching is the Extended Security Updates (延長安全更新, ESU) programme. ESU delivers critical and important security fixes on a yearly-renewal basis for up to three additional years, but eligibility and pricing differ sharply between segments:
| Segment | Eligibility | Year 1 cost | Escalation |
|---|---|---|---|
| Consumers (Windows 10 Home) | Single devices, Microsoft account required | ~US$30 | Increases each renewal year |
| Commercial (Pro, Enterprise, Education) | Volume Licensing, Microsoft 365 E3/E5, or Windows 365 | ~US$61 per device | Doubles each year, to a maximum of three years |
Cloud-managed devices enrolled in Windows 365 or Azure Virtual Desktop receive ESU coverage at no additional charge. IT budget cycles should treat ESU as a recurring line item rather than a one-off stopgap, and should plan for per-device costs that escalate sharply in years two and three.
Why this matters locally
Hong Kong's legacy Windows footprint tends to sit in the hardest-to-audit environments — POS terminals, kiosk displays, OT gateways, and embedded branch appliances — where a silent loss of update delivery is least likely to be detected before an incident forces the question. Any 2026 hardware-refresh plan should treat these cryptographic rotation dates as fixed deadlines and confirm ESU eligibility now, since enrolment windows close ahead of the rotation itself.
微軟警告,執行不再受支援 Windows 版本的電腦,在下一次 Windows Update 憑證輪換後,將會悄然停止接收安全更新。微軟強調此中斷屬於加密層面,而非行政性質——即簽署鏈的硬性斷裂,而非服務逐步惡化。
據 BleepingComputer 報導,該機制嚴格而言屬於加密性質:Windows Update 以依賴 SHA-2 演算法的憑證為更新進行簽署。無法驗證 SHA-2 code signature 的電腦,將無法在輪換完成後信任新的簽署鏈,從而完全停止收到更新提示——既無可見的錯誤訊息,一般監控系統亦不會標示此項故障。對管理員而言,實際影響是:一台已列入資產清單的裝置,可能會悄然脫離修補範圍,在管理儀表板上顯示一切正常,卻無限期地累積未修補漏洞。
受影響的平台
微軟指出以下版本缺乏所需的 SHA-2 支援,因此將在輪換後失去更新推送:
| 產品 | 支援狀態 |
|---|---|
| Windows Vista(所有版本) | 早已停止支援 |
| Windows 7 RTM(未安裝 Service Pack 1) | 已被 SP1 取代 |
| Windows 8 RTM(未安裝 Update) | 已被 Windows 8.1 Update 取代 |
| Windows Server 2003 / 2003 R2 | 早已停止支援 |
| Windows Server 2008 RTM(未安裝 SP) | 已被 SP2 取代 |
| Windows XP Embedded / POSReady | 延長支援期已屆滿 |
執行 Windows 7 SP1、Windows 8.1 Update 及其伺服器版本的裝置,只要已安裝 SHA-2 update stack,仍符合繼續接收更新的資格。微軟已發佈一項 servicing stack update,將 SHA-2 簽署驗證功能向下移植至上述平台。
延長安全更新(ESU)過渡方案
對於已在 2025 年 10 月 14 日停止支援的 Windows 10 而言,唯一獲得官方認可的持續修補途徑是 Extended Security Updates(延長安全更新,ESU)計劃。ESU 以按年續費形式提供重要及關鍵安全修補,最長可額外提供三年,惟不同客戶類別的資格及收費差異甚大:
| 客戶類別 | 資格 | 第一年費用 | 加價機制 |
|---|---|---|---|
| 個人用戶(Windows 10 Home) | 單一裝置,須使用 Microsoft 帳戶 | 約 30 美元 | 每次續費年遞增 |
| 商用用戶(Pro、Enterprise、Education) | 批量授權、Microsoft 365 E3/E5 或 Windows 365 | 每裝置約 61 美元 | 每年翻倍,最長三年 |
透過 Windows 365 或 Azure Virtual Desktop 管理的雲端裝置,可免費獲取 ESU 覆蓋。IT 預算週期應將 ESU 視為經常性開支項目,而非一次性權宜措施,並須為第二年及第三年急劇上升的每裝置成本作好規劃。
對本地有何影響
香港的舊版 Windows 裝機量往往集中在最難審計的環境,包括 POS 終端、自助服務機顯示屏、OT 閘道及分支機構的嵌入式裝置。在這些場景中,更新推送悄然中斷最不容易被察覺,直至事故發生才被迫正視問題。任何 2026 年的硬件更新計劃,都應將這些加密憑證輪換日期視為硬性期限,並立即確認 ESU 資格,因為申請期會在輪換正式生效前結束。
