EOL Software version showing on Patch/Compliance reports

Question asked by QM_SSJ4 on Jun 2, 2016

I've noticed EOL Software (.NET 4.0 and/or IE 8) showing up on Patch Reports and Scorecard Patch Reports (Compliance) even though scan reports are correctly detecting the EOL version. To state the obvious, EOL software no longer receive patches/updates it doesn't make sense to flag them needing latest cumulative and/or specific patch for supported versions. Yes, they should be flagged with the standard Sev 5 EOL QID and any missing patches available prior to EOL but not the latest. I don't recall this being the case before so I am wondering if something changed with the Patch Report changes that were  made a little while ago?