Bekker's Blog

Blog archive

Bounties Boosted for Busting Windows

Microsoft, an industry foot-dragger to bug bounties, seems satisfied with the results of the programs over the last few years.

The company has been offering financial rewards for the white hats who find security flaws in its products since 2012, with sporadic increases in bounty amounts and products covered, as well as occasional pop-up opportunities to find problems in select software, such as technical previews, before a specific deadline.

This week, Microsoft again expanded the scope of the products involved, and also bumped potential awards for bounties related to Hyper-V.

"In the spirit of maintaining a high security bar in Windows, we're launching the Windows Bounty Program on July 26, 2017," the company stated Tuesday in a blog post from the Microsoft Security Response Center team. "This will include all features of the Windows Insider Preview in addition to focus areas in Hyper-V, Mitigation bypass, Windows Defender Application Guard, and Microsoft Edge. We're also bumping up the pay-out range for the Hyper-V Bounty Program."

That payout range for bugs discovered in Hyper-V is now fairly large. Microsoft will pay $5,000 to $250,000 for Hyper-V bugs that meet certain criteria on the Windows 10, Windows Server 2012, Windows Server 2012 R2 and Windows Server Insider Preview platforms.

Outside of Hyper-V, a new base program for bugs found in the Windows Insider Preview can pay between $500 and $15,000. Focus area programs offer the same pay range for the Microsoft Edge browser, $500 to $30,000 for Windows Defender Application Guard, and $500 to $200,000 for "Mitigation Bypass Bounty and Bounty for Defense" in Windows 10.

That last category consists of two separate bounties, maxxing out at $100,000 each, for the same issue. Essentially, Microsoft is asking individuals to submit a novel mitigation bypass against the up-to-date Windows platform, as well as a separate defense idea that would block the exploitation technique.

Beyond the bounty programs launched or updated this week, Microsoft also offers ongoing bounties for bugs reported in Microsoft .NET Core, ASP.NET Core and in Microsoft cloud services. Those programs currently top out at $15,000.

The payouts are adding up. According to a bounty hunters honor roll that Microsoft maintains, the company has paid out over $1.5 million in bounties to date. The list includes three payouts of $100,000 bounties under the mitigation bypass category, and a $125,000 bounty for a mitigation bypass that was shared among three researchers.

Details about Microsoft Bounty Programs are available here.

Posted by Scott Bekker on July 27, 2017


Featured

  • Image of a futuristic maze

    The 2024 Microsoft Product Roadmap

    Everything Microsoft partners and IT pros need to know about major Microsoft product milestones this year.

  • Microsoft Sets September Launch for Purview Data Governance

    Microsoft's AI-powered Purview solution to address governance and security challenges is set to become generally available on Sept. 1.

  • An image of planes flying around a globe

    2024 Microsoft Conference Calendar: For Partners, IT Pros and Developers

    Here's your guide to all the IT training sessions, partner meet-ups and annual Microsoft conferences you won't want to miss.

  • End of the Road for Kaspersky in the United States

    Kaspersky on Monday said it is shuttering its U.S. operations, just days before a nationwide ban on sales of its security software was set to take effect.