A locked door with no locksmith left in business
Tenable plugin 176329 is not a vulnerability — it's a PCI DSS compliance check that flags software past its vendor-declared *End of Life* or *End of Support* date. The plugin enumerates installed packages, services, OS builds, and middleware (think Windows Server 2012 R2, RHEL 6, Apache 2.2, PHP 5.x, OpenSSL 1.0.2, Java 6/7/8 pre-Oracle, MySQL 5.5/5.6, Node 12/14, .NET Framework <4.6.2, etc.) and compares them against lifecycle databases. There are no CVE IDs attached — the finding is categorical: the vendor has stopped issuing security patches for this artifact, so any future flaw is permanently unpatched on this host.
Tenable scores this MEDIUM because, on a given scan day, there may be no *known unpatched* RCE against the EOL product. That severity is wrong for the PCI context this plugin lives in. PCI DSS Requirement 6.3.3 treats unsupported software as a *critical* control gap: it converts the host into a permanent exception that must be compensated, documented, and re-justified annually. Combined with the realistic threat picture — EOL OS/middleware are the highest-yield ransomware footholds of 2024-2026 (Akira, Black Basta, Cl0p all preference EOL boxes) — this is a HIGH finding on any in-scope CDE asset.
4 steps from start to impact.
Identify EOL surface
Shodan, Censys, banner grabs) or post-access enumeration (nmap -sV, winPEAS, LinPEAS) to fingerprint EOL versions. EOL software self-advertises through version banners that never change because the vendor will never ship another build.- Network reachability to the service OR initial foothold on adjacent host
- Internal-only services require an existing foothold
- Banner suppression / reverse-proxy normalization hides some versions
Select a public exploit that will never be patched
exploit/windows/smb/ms17_010_eternalblue for 2012R2-era hosts that missed backports, CVE-2022-22965 Spring4Shell on EOL Tomcat 8.5).- Public exploit exists for any post-EOL CVE in this product
- WAF / IPS signatures may catch generic payloads
- Some EOL products receive paid extended support (Microsoft ESU, Red Hat ELS) — check before assuming abandonment
Exploit and persist
Cobalt Strike, Sliver, Mythic.- Exploit lands; AV/EDR doesn't block
- EDR on the EOL host (if vendor supports it on the legacy OS)
- Network segmentation limits lateral movement
Pivot to PCI cardholder data
Mimikatz, Rubeus, secretsdump) and lateral movement (PsExec, Impacket, Evil-WinRM) to reach the payment application or database, then exfils via rclone or DNS tunneling.- Host is in PCI scope
- Network path to CDE
- Proper CDE segmentation (PCI Req 1.3) breaks this step
- DLP egress controls
The supporting signals.
| Finding type | Compliance / configuration audit — not a CVE. Plugin family: *Policy Compliance*. |
|---|---|
| PCI DSS reference | Requirement 6.3.3 (formerly 6.2 in v3.2.1) — *Security patches must be installed within one month; unsupported software is a deficiency requiring documented compensating controls.* |
| In-the-wild status | EOL software is the #1 initial-access enabler for ransomware in 2024-2026 per Mandiant M-Trends, Coveware, and Sophos State of Ransomware reports. |
| KEV alignment | CISA KEV contains 300+ entries that disproportionately affect EOL versions (e.g., MS17-010, ProxyLogon on unsupported Exchange, Log4Shell on EOL JDKs). |
| EPSS | N/A — plugin is not a single CVE. Underlying CVEs on EOL stacks routinely show EPSS > 0.90. |
| Typical triggers | Windows Server 2008/2012/2012R2 (post-ESU), Windows 7/8.1, RHEL/CentOS 6 (post-ELS), Ubuntu 14.04/16.04/18.04 (post-ESM), PHP 5.x/7.x, Java 6/7/8 (Oracle public-EOL), .NET Framework < 4.6.2, Apache 2.2, Tomcat 7/8, OpenSSL 1.0.x, Node 12/14/16, MongoDB 4.0/4.2, Python 2.7/3.6/3.7. |
| Vendor severity | MEDIUM per Tenable — generic, day-of-scan basis. |
| noisgate reassessment | HIGH — PCI scope + categorical patch-impossibility + favored ransomware target class. |
| Scanner coverage | Tenable 176329, Qualys 105170/45039, Rapid7 obsolete-software policy, Nessus *Unsupported* family. |
| Disclosure | Plugin published 2023-09; lifecycle data sourced from endoflife.date, vendor LTS pages, and Microsoft Lifecycle. |
noisgate verdict.
The decisive factor is PCI scope coupled with categorical un-patchability — every future CVE on this artifact lands on an asset the vendor has formally walked away from, and PCI DSS 6.3.3 treats that as a top-tier control gap. Tenable's MEDIUM reflects a single scan day; the *role multiplier* — these are typically OS/middleware on in-scope CDE hosts — floors the verdict at HIGH.
Why this verdict
- Categorical patch-gap: unlike a normal CVE, there is no fix coming — ever. Future zero-days against this artifact are permanently unmitigated.
- Role multiplier: the plugin overwhelmingly fires on OS, web server, runtime, and database tiers — canonical high-value-role components. A compromised EOL Windows Server in a CDE ends in domain or cardholder-data compromise; the high-value-role floor is HIGH.
- Compliance multiplier: PCI 6.3.3 requires documented compensating controls and annual risk acceptance. An unremediated finding here is an audit-grade defect, not a hygiene item.
- Threat-intel multiplier: Mandiant, Coveware, and Sophos 2025 reports all rank EOL OS/middleware as the top ransomware initial-access enabler — far above phishing for confirmed breaches in retail/hospitality (PCI verticals).
- Friction adjustment: the finding may fire on isolated lab hosts or out-of-scope dev boxes — those instances can be downgraded individually with documented scope evidence, but the default posture is HIGH.
Why not higher?
Not CRITICAL because the plugin itself is not weaponized exploitation — it's a state observation. Individual hosts may be isolated, behind segmentation, or covered by paid extended support (Microsoft ESU, Red Hat ELS, Ubuntu ESM) that materially changes the patch story. Without a paired KEV-listed CVE on the same host, the chain is not yet active.
Why not lower?
Not MEDIUM because the artifact will never be patched again, the host is by plugin-definition in a PCI compliance frame, and EOL stacks dominate ransomware case data. Treating this as a low-urgency finding has been a repeatable root cause in breach post-mortems across 2024-2026.
What to do — in priority order.
- Inventory and tag every EOL artifact this week — You cannot mitigate what you cannot enumerate. Pull the plugin output from Tenable.sc / Tenable.io, join against your CMDB, and tag each host with
eol_artifact,pci_scope, andbusiness_owner. Deadline: within 7 days as a HIGH-class finding (noisgate mitigation SLA = 30 days, but inventory is step zero). - Subscribe to paid extended support where it exists — Microsoft ESU (Windows Server 2012R2 through Oct 2026, 2008R2 retired), Red Hat ELS (RHEL 6 / 7), Canonical Ubuntu Pro / ESM, TuxCare ELS, and Oracle Sustaining Support buy you continued CVE patches. Within the noisgate mitigation SLA of 30 days — purchase, deploy the ESU keys/repos, and document.
- Network-segment and front-end with a reverse proxy / WAF — If you cannot retire the host, put it behind a WAF (modern TLS termination, request normalization) and a hard segmentation boundary so EOL TLS/HTTP stacks are never directly reachable. Apply NIST SP 800-82 / PCI 1.3 microsegmentation patterns. Complete within 30 days.
- Disable unneeded EOL services and harden surface — Turn off SMBv1, legacy TLS ciphers, anonymous binds, default accounts, and any non-essential listener on EOL hosts. Use vendor hardening guides (CIS Benchmarks for the closest supported version) as a baseline.
- Apply application-layer allowlisting — Deploy AppLocker / WDAC on Windows EOL or SELinux enforcing + fapolicyd on Linux EOL to prevent execution of attacker-introduced binaries. This is the single highest-yield control on a host that will never be patched.
- Increase EDR sensitivity on EOL hosts — Tune EDR to high-aggression mode on every host flagged by 176329, with priority alerting routed to the SOC on-call. EDR is the last meaningful layer when the OS will never ship a fix.
- Plan and budget retirement / re-platforming — Execute the noisgate remediation SLA — replace or upgrade within 180 days for HIGH. For PCI hosts, calendar this against your next QSA assessment so it doesn't become a recurring audit finding.
- Vulnerability patching alone: there are no patches to apply — the vendor has exited. Running Windows Update on Server 2012R2 without ESU does nothing.
- Antivirus signatures: legacy AV catches known malware but doesn't address the fundamental un-patchability of the platform.
- Risk-accepting the finding annually without compensating controls: PCI 6.3.3 specifically forbids this — acceptance must be paired with documented technical controls, not just a signature.
Crowdsourced verification payload.
Run on a Windows target host (or fan out via remoting / Tanium / SCCM). Invoke from an elevated PowerShell session: powershell -ExecutionPolicy Bypass -File .\Check-EOL.ps1. Requires local administrator to read OS build and full installed-software inventory. Outputs VULNERABLE, PATCHED, or UNKNOWN.
#requires -Version 3.0
# Check-EOL.ps1 — noisgate verifier for Tenable plugin 176329 (EOL software)
# Exits 1 = VULNERABLE (EOL detected), 0 = PATCHED (supported), 2 = UNKNOWN
$ErrorActionPreference = 'SilentlyContinue'
$findings = @()
# --- OS lifecycle check -------------------------------------------------
$os = Get-CimInstance Win32_OperatingSystem
$caption = $os.Caption
$build = [int]($os.BuildNumber)
# Microsoft lifecycle cutoffs (mainstream EOL; ESU may extend)
$eolMap = @{
'Windows 7' = '2020-01-14'
'Windows 8' = '2016-01-12'
'Windows 8.1' = '2023-01-10'
'Server 2008' = '2020-01-14'
'Server 2008 R2' = '2020-01-14'
'Server 2012' = '2023-10-10'
'Server 2012 R2' = '2023-10-10'
}
foreach ($k in $eolMap.Keys) {
if ($caption -match [regex]::Escape($k)) {
$findings += "OS EOL: $caption (vendor EOL $($eolMap[$k]))"
}
}
# --- .NET Framework -----------------------------------------------------
$ndp = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full' -ErrorAction SilentlyContinue
if ($ndp -and $ndp.Release -lt 394802) {
$findings += ".NET Framework < 4.6.2 (Release $($ndp.Release)) — EOL 2022-04-26"
}
# --- Installed software scan -------------------------------------------
$paths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$installed = Get-ItemProperty $paths | Where-Object DisplayName
$badPatterns = @(
@{Name='Java 6'; Re='Java\(TM\) 6|Java SE 6'},
@{Name='Java 7'; Re='Java\(TM\) 7|Java SE 7'},
@{Name='Java 8 (Oracle public EOL)'; Re='Java 8 Update'},
@{Name='PHP 5.x'; Re='PHP 5\.'},
@{Name='PHP 7.x'; Re='PHP 7\.'},
@{Name='Python 2.7'; Re='Python 2\.7'},
@{Name='Node 12/14/16'; Re='Node\.js.*v(12|14|16)\.'},
@{Name='OpenSSL 1.0.x'; Re='OpenSSL 1\.0\.'},
@{Name='Apache 2.2'; Re='Apache.*2\.2\.'},
@{Name='Tomcat 7/8'; Re='Apache Tomcat (7|8)\.'}
)
foreach ($p in $badPatterns) {
$hit = $installed | Where-Object { $_.DisplayName -match $p.Re }
if ($hit) { $findings += "EOL package: $($p.Name) — $($hit.DisplayName -join ', ')" }
}
# --- Verdict ------------------------------------------------------------
if ($findings.Count -gt 0) {
Write-Output 'VULNERABLE'
$findings | ForEach-Object { Write-Output " - $_" }
exit 1
} elseif (-not $os) {
Write-Output 'UNKNOWN'
exit 2
} else {
Write-Output 'PATCHED'
exit 0
}
If you remember one thing.
Sources
- Tenable Plugin 176329 — PCI DSS Compliance: Security End of Life Software
- PCI DSS v4.0.1 Requirements (Requirement 6.3.3)
- Microsoft Product Lifecycle
- endoflife.date — community lifecycle database
- Red Hat Enterprise Linux Life Cycle
- Ubuntu Pro / Expanded Security Maintenance
- CISA Known Exploited Vulnerabilities Catalog
- Mandiant M-Trends 2025
What defenders are saying.
Crowdsourced verification outputs.
Results submitted by users who ran the verification payload against their environment.