Microsoft is telling me they won’t issue a CVE for a vulnerability I reported because it is a cloud service and doesn’t require customer actions to fix. Which is quite literally not their policy. See link: msrc.microsoft.com/blog/2024/06/t…
- Had the same issue reporting this to AWS: aws.amazon.com/security/secur… Because customer can't patch, doesn't require AWS to give it a CVE...
- This is why people don't report them.
- Sell it next time 😂