hay guys I have a question....

lets say that I found a huge exploit/ flaw in MS SP2 security who would I report this to????? could someone end up in jail for finding an flaw such as this????

just a couple of questions I was curious about....