Earlier quoted context omitted.
OpenBSD would be perfect for the job, wouldn‘t it?
An OpenBSD machine still running unpatched from the XP era would be every bit as vulnerable.
For starters, Windows XP has always optimized for "plug random hardware in and it Just Works" while OpenBSD aims more at "what is the minimal number of services we can have running in the base image."
Sure, OpenSSL vulnerabilities found in the intervening time will still affect both, but we're still talking orders of magnitude difference in RCE vulnerabilities.