Well, with free products and services, our policy is "if you're not happy, we'll give you double your money back"
In this case at least reading through the timeline it sounds like the bulk of the discovery of the vulnerability came through paid folks though.
"shoulda put a ring on it"
Microsoft are being the twats here, not the ffmpeg devs