Researchers normally submit such findings to the Microsoft Security Response Center (MSRC) for patching to prevent hackers from exploiting them. But Nightmare Eclipse has deliberately ignored the responsible disclosure route, citing claims that Microsoft mistreated them.
“They mopped the floor with me and pulled every childish game they could,” the researcher wrote last month, without elaborating. “It was soo bad at some point I was wondering if I was dealing with a massive corporation or someone who is just having fun seeing me suffer but it seems to be a collective decision.”



This is the best option when dealing with companies like MS. Some companies actually use reports, issue CVEs, acknowledge shit… MS does not, fuck them. Sell the 0day to a company that will go on to sell it to a state actor, MS will patch it eventually but you won’t be treated like shit to keep it under the rug.