News

Microsoft Extends $15,000 per-Bug Bounty Program

Microsoft is extending their MS Office Bounty Program until the end of 2017. The program originally was only to last until June 15. However, the software giant is happy with their engagement with the security community that an extension makes sense. The program’s introduction in March includes a $500 minimum with up to $15,000 per-bug bounty. Which is for for any valid vulnerabilities and zero-day flaws in the Microsoft Office Insider slow build. Of course, this is on a full patch Windows 10 desktop operating system. Plus, there is a stipulation that Microsoft must be able to replicate it.

To sweeten the deal further, they are increasing the minimum bounty to $6,000, while the cap is still at $15,000. It is easy to assume that the the easier bugs have already been found, leaving only some harder to find ones. Increasing the bounty should help motivate the security community further. In the bounty terms available on the TechNet blog, Microsoft is specifically looking for zero-day problems including privilege escalation through Office Protected View, macro execution which bypasses security barriers designed to block macros, and remote code execution bugs, among others.

How does Microsoft Set the Payment Amounts?

If multiple submissions of the same bug report from several parties come in, the bounty only goes to the first eligible submission. However, if the duplicate report provides additional information that helps the vulnerability investigation, they may still provide a reward.

For more information on the terms of the bounty, visit the MS Office Insider bounty program page at: https://technet.microsoft.com/en-us/mt797549.aspx

Ron Perillo

Disqus Comments Loading...

Recent Posts

Electronic Arts Titles Played for Over 11 Billion Hours in 2024

Electronic Arts (EA) announced today that its games were played for over 11 billion hours…

2 days ago

Just 15% of Steam Gaming Time in 2024 Was Spent on New Releases

Steam's annual end-of-year recap, Steam Replay, provides fascinating insights into gamer habits by comparing individual…

2 days ago

STALKER 2 Gets Massive 110GB Patch With 1800+ Fixes

GSC GameWorld released a major title update for STALKER 2 this seeking, bringing the game…

2 days ago

Intel Unveils Core 200H Processors Based on the Previous Raptor Lake Refresh

Without any formal announcement, Intel appears to have revealed its new Core 200H series processors…

3 days ago

Ubisoft Reportedly Developing a New Quadruple A Game

Ubisoft is not having the best of times, but despite recent flops, the company still…

3 days ago

STALKER 2: Heart of Chornobyl Update 1.1 Fixes 1,800 Issues and Revamps A-Life 2.0

If you haven’t started playing STALKER 2: Heart of Chornobyl yet, now might be the…

3 days ago