Microsoft Defender Incorrectly Flags SQL Server Software as End-of-life
Microsoft Defender for Endpoint has been incorrectly flagging certain versions of SQL Server as end-of-life, potentially causing confusion for system administrators.
Microsoft Defender for Endpoint has been incorrectly flagging certain versions of SQL Server as end-of-life, potentially causing confusion for system administrators.
This issue, tracked under advisory DZ1168079 , originates from a code bug affecting the Threat and Vulnerability Management feature within the Microsoft Defender XDR suite.
The bug specifically impacts organizations using SQL Server 2017 and 2019. Within the Microsoft Defender for Endpoint portal, administrators may incorrectly see an "End-Of-Support" (EOS) tag applied to these software versions.
Microsoft has clarified that while the EOS tag is erroneous, the associated vulnerability recommendations remain valid and should be addressed.
This mislabeling situation requires administrators to act on legitimate security alerts while disregarding the incorrect end-of-life status.
The impact is significant as it could affect any environment deploying these SQL Server versions with Defender for Endpoint for security management.
The bug specifically impacts organizations using SQL Server 2017 and 2019.
According to Microsoft, the issue originated from a recent change related to End-Of-Support software detection, which introduced a code problem.
The service degradation officially began on Wed, Oct 8, 2025, although Microsoft’s incident timeline traces the start back to Mon, Sep 29, 2025. Initially, false positive vulnerability recommendations were reported.
However, after further investigation, it was found that the vulnerability reports were accurate, but the EOS tags were incorrectly applied.
In response, Microsoft developed a fix to correct the faulty code and began deploying it to its test environment for validation before a wider rollout.
Despite initial remediation efforts, the problem persists. Microsoft confirmed on Thu, Oct 9, that after deploying the fix, inaccurate end-of-life tagging was still occurring for some users.
This indicates that the first attempted solution was not entirely effective. The company’s engineers are now investigating additional actions necessary to ensure the fix resolves the issue for all affected customers.
The service status remains at "serviceDegradation," and Microsoft has committed to providing its next update by Sun, Oct 12, 2025.
In the interim, administrators are advised to acknowledge the validity of the vulnerability alerts for SQL Server 2017 and 2019 but disregard the incorrect end-of-life notifications.
Based on reporting by Cyber Security News.
