A big reason for why this is in my opinion, is not that they don't want to get an update, it's because of corporate politics. Someone has to be the manager that goes "boss, I want to spend money and resources to update an essential service and doing so will increase security and productivity." What is heard "<underling> boss, I want to spend money".
Bosses never want to spend a cent, because of the "shareholders". They also don't want to say "yes" to something because if there is an issue, it is then their fault even if it was worth doing. They would rather kick the can down the road until the wheels come flying off the car.
This is why nothing ever gets updated.