A client needs to have .NET Framework 4
installed and not patched so their software running on their Windows 2008 R2 Server
functions properly.
This sparks the questions:
- When is it okay to house a vulnerable framework if their application is not compatible with the latest framework version?
- What are best practices in this situation?
Perhaps this question should be in SE: Information Security?