IE9 pwn2owned with 0-day with exploit working back from IE6 to IE10 on Windows 8
zdnet.com
zdnet.com
I'm trying to think of why else they wouldn't disclose the protected mode bypass error, but instead keep it "private for our customers".
Another possibility I had in mind is that they want to get paid by people wanting to fix this vulnerability on their systems. eg, company X will have to come to them if they want their IE browsers to receive the patch against this bug.
I am trying to imagine a situation where _lawfuly_ government agencies need to break into someones IE. Any ideas?
Therefore, you "legitimate" search warrant will be thrown out of window by a judge, and classified as the Fruit of the poisonous tree.
The only way to get the IE team to fix issues is make a public spectacle like Vupen did. And I completely get only exposing bugs when there is a profit to be made, because any other route is counterproductive.