How is sending a patch level a vulnerability? It only makes things easier to scan, not to exploit.
(And you shouldn't trust that data anyway.)
(And you shouldn't trust that data anyway.)
Or a scan becomes that much easier to perform on 100,000 endpoints - and then your targeted attacks can begin on only vulnerable systems. 'Exploiters' waste a lot of time trying non-vulnerable systems.
The less information your server exposes to the outside, the better.