In that case, it would be Microsoft's fault, imho. He mailed it to them, but if there is no reaction, then it's their fault, imho.
But before putting it on a web-site, I would've mailed it to a *serious* magazine or to BugTraq or so, just to make sure the security-related persons get it first.