Microsoft Reasserts Coordinated Disclosure Norms After Researcher Drops Zero-Days

Redmond is invoking CVD principles after a researcher publicly posted unpatched flaws, raising fresh questions about the boundary between disclosure ethics and platform enforcement.

ThreatVectr Newsdesk· 2 min read
Microsoft Reasserts Coordinated Disclosure Norms After Researcher Drops Zero-Days
Share

Microsoft has restated its position on Coordinated Vulnerability Disclosure, asking researchers to give vendors a window to triage and patch before flaws hit the public record.

The statement followed a public drop of multiple zero-days by a researcher operating under the handles Chaotic Eclipse and Nightmare-Eclipse.

The company's framing matters. CVD is not law. It is a norm, codified in industry practice and in standards like ISO/IEC 29147 on vulnerability disclosure and ISO/IEC 30111 on handling processes. Microsoft's own program terms sit on top of that scaffolding.

Neither standard carries an enforcement trigger against an independent researcher. What they do is set expectations for vendor behavior — acknowledgment timelines, remediation cadence, credit — in exchange for which researchers are asked to hold publication.

That bargain only works if both sides perform.

The researcher's posts, since removed from the hosting platform, included proof-of-concept material for issues Microsoft says were not reported through its Security Response Center intake. MSRC's published policy, available at the MSRC researcher portal, asks for private submission and offers bounty eligibility under the terms of each specific program.

Public, pre-patch disclosure forfeits that eligibility. It does not, on its own, violate U.S. law. The Department of Justice's 2022 CFAA charging policy explicitly declines to prosecute good-faith security research, though the policy is a charging guideline rather than a safe harbor codified in statute.

Platform terms are a different matter. Code-hosting providers retain broad contractual discretion to remove repositories containing active exploit code, and account takedowns in this category are routine.

Microsoft's appeal lands in a regulatory environment that increasingly pulls vulnerability handling into formal rule. The EU's Cyber Resilience Act, which entered into force in December 2024, requires manufacturers to report actively exploited vulnerabilities to ENISA within 24 hours of awareness under Article 14. Most obligations apply from December 11, 2027.

In the U.S., CISA's CIRCIA final rule remains pending. The notice of proposed rulemaking closed its comment period on July 3, 2024, and the agency has signaled a final rule by late 2025. Neither regime regulates third-party researcher conduct directly. Both raise the stakes for how vendors document what they knew and when.

That is the subtext of Microsoft's statement. A vendor that learns of a flaw via a public post, rather than a private report, has a much harder time meeting a 24- or 72-hour clock with anything more than an acknowledgment.

The affected CVEs, if any have been assigned, were not identified in Microsoft's communication. Researchers seeking to coordinate can submit through the MSRC portal; bounty terms are listed per product family on the Microsoft Bug Bounty page.

© 2026 Threat Vectr