Microsoft has release a new statement regarding the Coordinated Vulnerability Disclosure.

What’s missing is the fact how long we must wait until we know about the vulnerability’s. Normally we know it then when Microsoft got a patch to deliver to us via the Update Service….so sometimes we got to wait for weeks or even month for the information about a vulnerability. During this time, Hacker’s can use this vulnerability to install Viruses and security-software- company’s can not deliver new signatures to protect our systems.

Microsoft is not alone with this strategy, it is common to act like this in the software business. Open Source Software is an exception, normally we know it earlier if there is a vulnerability.

Well if some security-researcher’s need space to present the vulnerability to us, I will give you some space on my website…or maybe we still got to visit the hacker websites to keep us informed about the latest vulnerability’s ;-)