Story image

US$250,000 up for grabs with Microsoft’s bug bounty

19 Mar 2018

Microsoft has placed a quarter of a million dollar bounty on bugs with the Speculative Execution Side Channel Bounty Program.

Speculative Execution Side Channels are a hardware vulnerability class that affects CPUs from multiple manufacturers.

Through this program, people will have the opportunity to submit novel speculative execution side channel vulnerabilities and mitigation bypasses that affect Microsoft’s latest Windows and cloud platforms.

Qualified submissions are eligible for payment of up to USD$250,000. All bounties will be awarded at Microsoft's discretion.

The qualifying submissions will also be shared with industry partners in order to coordinate disclosure and protections for customers.

There are some Ts & Cs that you should be aware of if you are intending to submit and Microsoft asks that if the technique was involved or witnessed in an actual attack that the information is included in the submission.

Eligible vulnerability submissions must include a white paper or a brief document explaining the exploitation method and must target a particular scenario.

They must also demonstrate and describe an exploitation method that is reliable, reasonable, impactful, novel, and for the latest version of their software.

There are four tiers of submission, the lowest being ‘Exploitable speculative execution vulnerabilities’ which are eligible for up to USD$25,000,

‘Windows speculative execution mitigation bypass’ then ‘Azure speculative execution mitigation bypass’ follow, which can both net up to USD$200,000.

The top tier is ‘New categories of speculative execution attacks’ which max out at the full $250,000.

Additional factors that are considered when assessing payouts include how broadly applicable the side channel attack may be, the perceived level of difficulty and reliability in making use of the technique, and the overall impact of the attack.

The aim of the bug bounty program is to uncover novel vulnerabilities that have a direct and demonstrable impact on the security of users and our users' data.

The following are examples of vulnerabilities that will not earn a bounty reward under this program:

  • Tier 3 and 4 vulnerabilities in anything earlier than the current WIP fast build
  • Vulnerabilities in any versions of Internet Explorer
  • Vulnerabilities in any versions of Adobe Flash
  • Microsoft Edge Timer mitigation bypasses of variant 1 (Tier 4)

Microsoft has also said that they reserve the right to reject any submission.

ForgeRock launches Sandbox-as-a-Service to facilitate compliance
The cloud-based testing environment for APIs enables banks to accelerate compliance with Open Banking and PSD2 deadlines.
Huawei picks up accolades for software-defined camera ecosystem
"The company's software defined capabilities enable it to future-proof its camera ecosystem and greatly lower the total cost of ownership (TCO), as its single camera system is applicable to a variety of application use cases."
Tech community rocked by deaths of Atta Elayyan and Syed Jahandad Ali
Both men were among the 50 killed in the shooting in Christchurch last Friday when a gunman opened fire at two mosques.
Ingram Micro gives Cloud Marketplace an overhaul
Including a new UI, improved sales and marketing tools, and an API for integrating a partner’s own storefront, CRM and billing.
NZ ISPs block internet footage of Christchurch shootings
2degrees, Spark, Vodafone and Vocus are now blocking any website that shows footage of the mosque shootings.
Barracuda expands MSP security offerings with RMM acquisition
Managed Workplace delivers an RMM platform with security tools and services, such as site security assessments, Office 365 account management, and integrated third-party antivirus.
SolarWinds extends database anomaly detection
As organisations continue their transition from purely on-premises operations into both private and public cloud infrastructures, adapting their IT monitoring and management capabilities can pose a significant challenge.
HP extends laptop & workstation recall due to battery fire hazard
HP has extended its worldwide recall of several notebooks and mobile workstations due to the high risk of fire and burn hazards.