I've just heard someone *seriously* suggest that if a scanner finds a vulnerability in (for example) Microsoft Teams, even if there is no fix available from the vendor (Microsoft) we should patch the component with the latest file version from the upstream provider (often open source maintainers). Bear in mind where this is a file version detection, there's no evidence that its actually exploitable (e.g. the impacted functionality may not even be used by the parent product). For someone in Information Security to suggest this seems absolutely bananas, but am I missing something? #vulnerability #vulnerabilitymanagement #compliancetheater #cyberessentials