Bekker's Blog

Blog archive

Bounties Boosted for Busting Windows

Microsoft, an industry foot-dragger to bug bounties, seems satisfied with the results of the programs over the last few years.

The company has been offering financial rewards for the white hats who find security flaws in its products since 2012, with sporadic increases in bounty amounts and products covered, as well as occasional pop-up opportunities to find problems in select software, such as technical previews, before a specific deadline.

This week, Microsoft again expanded the scope of the products involved, and also bumped potential awards for bounties related to Hyper-V.

"In the spirit of maintaining a high security bar in Windows, we're launching the Windows Bounty Program on July 26, 2017," the company stated Tuesday in a blog post from the Microsoft Security Response Center team. "This will include all features of the Windows Insider Preview in addition to focus areas in Hyper-V, Mitigation bypass, Windows Defender Application Guard, and Microsoft Edge. We're also bumping up the pay-out range for the Hyper-V Bounty Program."

That payout range for bugs discovered in Hyper-V is now fairly large. Microsoft will pay $5,000 to $250,000 for Hyper-V bugs that meet certain criteria on the Windows 10, Windows Server 2012, Windows Server 2012 R2 and Windows Server Insider Preview platforms.

Outside of Hyper-V, a new base program for bugs found in the Windows Insider Preview can pay between $500 and $15,000. Focus area programs offer the same pay range for the Microsoft Edge browser, $500 to $30,000 for Windows Defender Application Guard, and $500 to $200,000 for "Mitigation Bypass Bounty and Bounty for Defense" in Windows 10.

That last category consists of two separate bounties, maxxing out at $100,000 each, for the same issue. Essentially, Microsoft is asking individuals to submit a novel mitigation bypass against the up-to-date Windows platform, as well as a separate defense idea that would block the exploitation technique.

Beyond the bounty programs launched or updated this week, Microsoft also offers ongoing bounties for bugs reported in Microsoft .NET Core, ASP.NET Core and in Microsoft cloud services. Those programs currently top out at $15,000.

The payouts are adding up. According to a bounty hunters honor roll that Microsoft maintains, the company has paid out over $1.5 million in bounties to date. The list includes three payouts of $100,000 bounties under the mitigation bypass category, and a $125,000 bounty for a mitigation bypass that was shared among three researchers.

Details about Microsoft Bounty Programs are available here.

Posted by Scott Bekker on July 27, 2017 at 12:10 PM


Featured

  • Microsoft Invests $1 Billion in Next-Level AI Research

    Research outfit OpenAI and Microsoft have inked a $1 billion deal around artificial general intelligence (AGI), considered the holy grail of AI research.

  • Microsoft Streamlining Office 365 App Activations

    The Office 365 app installation experience should get a little easier for end users starting as early as next month.

  • The 2019 Microsoft Product Roadmap

    From the next major update to Windows 10 to the next generation of HoloLens, here's what's on tap from Microsoft this year.

  • 2019 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss this year.