Having read all the whining in this thread, the same ridiculous argument redundantly keeps being made. And if it was directly answered this way I missed it. So I'll jump in here.
So, the argument is that 90 days came just 2 days before Microsoft's patch Tuesday. And that Microsoft wanted to wait 2 days until their official Tuesday release schedule. And people think that they should have had that extra 2 days grace period to prevent an announcement from being made.
That's ridiculous.
So, let's suppose that Microsoft had the patch ready on Wednesday of last week. Tuesday has already passed. It's ready for release, but Tuesday is now a week away. Because they only release fixes on a Tuesday, a vulnerability should be left in place for no reason other than because it's not a Tuesday???? That's just stupidity.
Fixes should be made available the moment they are ready. Microsoft apparently had it ready. They just didn't want to give it to us because it wasn't a Tuesday. Ridiculous.
People apparently take their security quite lightly. How about this.... You find out that the locks on your house aren't working properly and the door randomly swings open. You call the locksmith and he says oh yeah, I can fix that. And it'll only take 5 seconds. You can either bring the locks to me or I'll come to you. You say, great, how soon can you be here. He says actually I'm right next door, and I'm not busy at the moment. But my policy is to only fix that particular issue on a Tuesday, and today is Wednesday. I have nothing else going on this week that would prevent me from fixing it, I just only fix that particular problem on Tuesdays.
Now let's see how much you defend that locksmith. Now imagine he's the only guy in town who could possibly fix your door.
Hope you have nothing better to do for a week besides sit at home and lean against the door to hold it closed.
The 90 day policy gives companies plenty of time to fix the issue. A company deciding to sit on a fix just because today isn't Tuesday is ridiculous. There is no reason other than thick headedness to sit providing a software patch because today isn't Tuesday.