Story image

US$250,000 up for grabs with Microsoft’s bug bounty

19 Mar 18

Microsoft has placed a quarter of a million dollar bounty on bugs with the Speculative Execution Side Channel Bounty Program.

Speculative Execution Side Channels are a hardware vulnerability class that affects CPUs from multiple manufacturers.

Through this program, people will have the opportunity to submit novel speculative execution side channel vulnerabilities and mitigation bypasses that affect Microsoft’s latest Windows and cloud platforms.

Qualified submissions are eligible for payment of up to USD$250,000. All bounties will be awarded at Microsoft's discretion.

The qualifying submissions will also be shared with industry partners in order to coordinate disclosure and protections for customers.

There are some Ts & Cs that you should be aware of if you are intending to submit and Microsoft asks that if the technique was involved or witnessed in an actual attack that the information is included in the submission.

Eligible vulnerability submissions must include a white paper or a brief document explaining the exploitation method and must target a particular scenario.

They must also demonstrate and describe an exploitation method that is reliable, reasonable, impactful, novel, and for the latest version of their software.

There are four tiers of submission, the lowest being ‘Exploitable speculative execution vulnerabilities’ which are eligible for up to USD$25,000,

‘Windows speculative execution mitigation bypass’ then ‘Azure speculative execution mitigation bypass’ follow, which can both net up to USD$200,000.

The top tier is ‘New categories of speculative execution attacks’ which max out at the full $250,000.

Additional factors that are considered when assessing payouts include how broadly applicable the side channel attack may be, the perceived level of difficulty and reliability in making use of the technique, and the overall impact of the attack.

The aim of the bug bounty program is to uncover novel vulnerabilities that have a direct and demonstrable impact on the security of users and our users' data.

The following are examples of vulnerabilities that will not earn a bounty reward under this program:

  • Tier 3 and 4 vulnerabilities in anything earlier than the current WIP fast build
  • Vulnerabilities in any versions of Internet Explorer
  • Vulnerabilities in any versions of Adobe Flash
  • Microsoft Edge Timer mitigation bypasses of variant 1 (Tier 4)

Microsoft has also said that they reserve the right to reject any submission.

Disruption in the supply chain: Why IT resilience is a collective responsibility
"A truly resilient organisation will invest in building strong relationships while the sun shines so they can draw on goodwill when it rains."
The disaster recovery-as-a-service market is on the rise
As time progresses and advanced technologies are implemented, the demand for disaster recovery-as-a-service is also expected to increase.
Cohesity signs new reseller and cloud service provider in Australia
NEXION Networks has been appointed as an authorised reseller of Cohesity’s range of solutions for secondary data.
The key to financial institutions’ path to digital dominance
By 2020, about 1.7 megabytes a second of new information will be created for every human being on the planet.
Proofpoint launches feature to identify most targeted users
“One of the largest security industry misconceptions is that most cyberattacks target top executives and management.”
What disaster recovery will look like in 2019
“With nearly half of all businesses experiencing an unrecoverable data event in the last three years, current backup solutions are no longer fit for purpose."
NVIDIA sets records with their enterprise AI
The new MLPerf benchmark suite measures a wide range of deep learning workloads, aiming to serve as the industry’s first objective AI benchmark suite.
McAfee named Leader in Magic Quadrant an eighth time
The company has been once again named as a Leader in the Gartner Magic Quadrant for Security Information and Event Management.