I know that they should have installed the Cumulative update, but there's some MIS that I know refrain from install patches to their system, fearing it'll break their programs. Given that they haven't installed something they should have installed 3 years ago, I'm afraid that they'll go to the "code route" if someone said it's possible.
Don't laugh... at my previous company, we have a client that is a bank still doing UAT for 20+ earlier release of our company's flagship server software... Things are like dead water that won't move forward...