There are two methods of revoking a certificate, Certificate Revocation Lists and OCSP (Online Certificate Status Protocol).
CRL lists do not scale at all and are almost universally do not include all revoked certificates (startssl implements this correctly which is why they charge $25 to revoke a certificate).
OCSP is susceptible to a MitM attack (exactly the scenario in which you want it to work!).
An attacker can simply block OCSP requests and nearly all current browsers will silently ignore the failure.
They ignore such a failure because they are actually very common. The CA has to run an OCSP server that is queried continuously at high volume for no additional revenue, a model that doesn't exactly encourage robust operation.
The only way to effectively revoke certificates in the numbers necessary after heartbleed is for the CAs to revoke their intermediary certs and have everybody get a new cert free of charge.
Edit: for example here is the digicert CRL http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl