← Microsoft Corporation cases
Bugzilla #1906028 Self Reported Incident Audit Finding

Microsoft PKI Services: Vulnerability Management Exception Tracking

RESOLVED FIXED Microsoft Corporation
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is a self-disclosure by Microsoft PKI Services about deficiencies found during an audit period in its Vulnerability Management process. The auditors issued a qualified opinion stating that, upon discovery of a Critical Vulnerability, certain required actions did not occur within 96 hours, which caused WebTrust Principles and Criteria for Certification Authorities – Network Security – Version 1.0 to not be met. Microsoft reported that when exceptions to the 96-hour remediation timeline occurred, the vulnerability mitigation plan and timelines were known internally but were not consistently documented and attached to the vulnerability tracker, and the vulnerability dashboard did not display the remediation plan for exceptions. Microsoft stated that no certificates were impacted by this process issue. Microsoft opened and updated this bug with a root cause analysis and action items to document mitigation plans for 96-hour exceptions and to expand the vulnerability tracking dashboard to include additional fields, including the mitigation plan. Microsoft later reported completing both action items and asked whether the bug could be closed; Mozilla indicated it would close the bug on 9-Aug-2024 unless further discussion was needed. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:23 UTC Confidence: 0.90 5 comments
Chronology
  1. Audit period ended; auditors issued a qualified opinion identifying deficiencies in Microsoft PKI Services vulnerability mitigation documentation and timelines.
  2. Auditor provided draft audit reports containing the qualified opinion.
  3. Microsoft PKI Services opened the Bugzilla case in response to the audit finding.
  4. Microsoft reported completion of documenting mitigation plans for 96-hour exceptions and set a due date for dashboard expansion.
  5. Microsoft reported completion of the remaining dashboard action item and requested closure.
  6. Bug status was updated to RESOLVED (FIXED).
Thread Activity
  1. Disabled representative — Microsoft submitted an incident report describing the qualified audit finding, the impact on producing evidence for documented mitigation plans during >96-hour exceptions, and action items to document mitigation plans and update the vulnerability tracking dashboard.
  2. Disabled representative — Microsoft posted an updated incident report with the same qualified-opinion language and reiterated the root cause and action items.
  3. Disabled representative — Microsoft reported it completed the action item to document mitigation plans for 96-hour exceptions and provided a due date for expanding the dashboard.
  4. Disabled representative — Microsoft stated it completed the final action item (dashboard expansion) and asked if the bug could be closed.
  5. Mozilla representative — Mozilla responded that it would close the bug on Friday, 9-Aug-2024, unless discussions were needed.
Participants
Disabled representative Mozilla representative
External References
Similar Local Cases
#1848279 RESOLVED Self Reported Incident Opened 2023-08-11 · Closed 2023-10-12 · 98% similar
Microsoft PKI Services: Trusted Role Control Failure
#1848280 RESOLVED Self Reported Incident Opened 2023-08-11 · Closed 2023-10-12 · 97% similar
Microsoft PKI Services: 3-Month Access Review Process Failure
#1705419 RESOLVED Certificate Misissuance Self Reported Incident Opened 2021-04-15 · Closed 2023-02-22 · 87% similar
Microsoft PKI Services: Underscore in SAN
#1711147 RESOLVED Self Reported Incident Opened 2021-05-13 · Closed 2023-02-22 · 87% similar
Microsoft PKI Services: Malformed ICAs (missing certificate policy extensions)
#1793443 RESOLVED Self Reported Incident Opened 2022-10-03 · Closed 2024-05-09 · 86% similar
Microsoft PKI Services: "unknown" OCSP response for issued certificates
#2026452 RESOLVED Self Reported Incident Audit Delay Opened 2026-03-26 · Closed 2026-04-22 · 81% similar
Microsoft PKI Services: Failure to publish Full Incident Report for Bugzilla 2021175 within 14 days
#1602999 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Opened 2019-12-11 · Closed 2024-05-09 · 81% similar
Microsoft PKI Services: Loss of Archived Firewall logs from Retention Store
#1979475 RESOLVED Self Reported Incident Certificate Misissuance Opened 2025-07-26 · Closed 2026-01-20 · 81% similar
Microsoft PKI Services: End Entity Certificate Mis-issuance against CPS (BasicConstraints)

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action