Microsoft calls for coordinated vulnerability disclosure after zero-day disclosures put customers at risk
By
MSRC
A good honest bake. Not flashy, but you'll finish the whole bagel.
Summary
Microsoft addresses the recent public disclosure of zero-day vulnerabilities that were not shared with the company beforehand, putting customers at risk. The article emphasizes the importance of Coordinated Vulnerability Disclosure (CVD), the industry standard where researchers share findings with affected vendors before public release, allowing time to understand and address the impact. Microsoft highlights its ongoing partnership with hundreds of security researchers through this process.
Key quotes
· 3 pulledThe details of these vulnerabilities were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk.
Every year, we work with hundreds of security researchers through Coordinated Vulnerability Disclosure (CVD) – the industry standard that asks researchers to share their findings with affected vendors.
This partnership allows us to make updates to impacted services
You might also wanna read
CVE-2025-53136: Microsoft Patches Windows Kernel Information Disclosure Vulnerability Bypassing KASLR
Microsoft patched CVE-2025-53136, a kernel information disclosure vulnerability in Windows NT OS Kernel that allowed leaking kernel base add
Google Project Zero Addresses the 'Patch Gap' in Vulnerability Disclosure
The article discusses Google Project Zero's updated vulnerability disclosure policy, the '90+30' model, introduced in 2021 to accelerate pat
Critical Misconfiguration in Microsoft's Internal Applications Exposes Sensitive Data
The article details a security researcher's discovery of a critical misconfiguration in Microsoft's internal applications, which allowed una
research.eye.security·9mo agoChallenges of Coordinated Vulnerability Disclosure in Belgium
The article discusses the author's experience with coordinated vulnerability disclosure (CVD) in Belgium and why they believe Belgium is uns
Anonymous researcher releases two new Windows zero-day exploits after Patch Tuesday
An anonymous security researcher (Nightmare-Eclipse/Chaotic Eclipse) has released two new Windows zero-day exploits — YellowKey (a BitLocker
