CVE-2017-7269 and abandonware

Who issued CVE-2017-7269 (IIS 6 WebDAV vulnerability)?


What are the assignment rules for abandonware (or unsupportedware)?

Is the vendor CNA primarily responsible, if one exists?

Next, is it up to a more generic CNA like MITRE, DWF, CERT/CC, 

 - Art

