A) Security Researchers should not disclose
vulnerabilities.
B) Security Researchers should not disclose
vulnerabilities before the vendor has a
chance to patch them.
C) Security Researchers should aggressively
disclose on a 30-60 day time frame.
D) Security Researchers should disclose within a week.
I'll presuppose that your answer will be "E - it depends" - so let's restrict it to this _particular_ vulnerability.My answer is C), but only because I realize that the squeaky wheel _really_ gets the grease, and that the threat of disclosure really, really inspires developers to Lab, Replicate, Solve, and deploy a fix. My answer is not D), because I believe more harm is done by disclosing vulnerabilities where there is _no chance_ of a patch being completed in time. Tavis Ormandy clearly believed the answer was D) in this case.
Also, of all vendors, Microsoft is actually pretty good (not perfect) about getting regular security patches out on a monthly basis - I'd have to believe that they probably prioritized this one fairly high.