The CVE That Wasn’t: Microsoft’s Azure Vulnerability Rejection and the Eroding Trust in Cloud Disclosure
A researcher discovered a critical cross-tenant access flaw in Azure’s identity management layer and submitted a detailed report with PoC code. Microsoft’s Security Response Center rejected it as “by design,” refusing to issue a CVE. This analysis examines the inconsistent precedent, the shared resp