Been a while, but here’s mine:
* I found out that I can use email certificate as a CA certificate on Windows;
* MSRC wasn’t interested, thinking it’s Verisign problem;
* I posted the issue to SecurityFocus;
* Some guy stood up server with fake cert on the Internet;
* Microsoft issued a patch.
Also: it’s secure@microsoft.com because security@ was the campus guards.
Since everyone is sharing MSRC stories 🙃
I had a PrivEsc from User Admin, a role many give helpdesk or HR, to Global Admin
MSRC: Not a vulnerability, requires a built-in Microsoft app in the tenant to exploit
Also MSRC: It's a vulnerability when someone else submits it🤷♂️