Microsoft released KB5028222, a monthly security rollup for Windows Server 2008 SP2, covering miscellaneous security improvements to internal Windows OS functionality and bundling fixes previously included in KB5027279. Related Microsoft support material also references KB5028185 for newer Windows builds, indicating the update was part of a broader Patch Tuesday release set.
The company said Windows Server 2008 SP2 is no longer generally supported and that security updates are limited to eligible Azure-based deployments enrolled in the fourth and final year of Extended Security Updates (ESU). Microsoft warned that installation can fail on unsupported editions or on systems missing a properly installed and activated ESU MAK add-on key, and it listed prerequisite servicing stack, SHA-2, and ESU licensing preparation updates required before deployment through Windows Update, the Microsoft Update Catalog, or WSUS.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft states that the fourth and final year of Extended Security Updates for eligible Azure-based Windows Server 2008 SP2 deployments runs through January 9, 2024.
Microsoft published the July 11, 2023 security updates including KB5028185 for OS Build 22621.1992 and KB5028222 as the monthly rollup for Windows Server 2008 SP2. The KB5028222 guidance notes miscellaneous security improvements and documents installation prerequisites and a known failure scenario for unsupported or improperly licensed systems.
Microsoft released update KB5027279, whose improvements were later incorporated into the July 2023 monthly rollup for Windows Server 2008 SP2.
Microsoft states that a fourth and final year of Extended Security Updates for Windows Server 2008 SP2 is available only for eligible Azure-based deployments beginning February 14, 2023.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.