Arguably, that's exactly what VUPEN is doing here. They're keeping it secret, and only letting those who are willing to pay have the necessary knowledge regarding this vulnerability and any possible workarounds. It might not be a scam, but I do find it morally questionable to hide the details of a bug of this significance.