Microsoft now confirmed that because the vulnerability I reported is important, not critical, and because they’ve now fixed it they won’t issue a CVE. It’s like they actually want to discourage people from reporting.
Microsoft is telling me they won’t issue a CVE for a vulnerability I reported because it is a cloud service and doesn’t require customer actions to fix. Which is quite literally not their policy. See link: msrc.microsoft.com/blog/2024/06/t…