Vulnerabilities / Threats
6/19/2013
03:31 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Microsoft Dangles $100,000 Bug Bounty

One hitch: The bugs might be worth more on the open market.

Google Apps To Microsoft Office 365: 10 Lessons
Google Apps To Microsoft Office 365: 10 Lessons
(click image for larger view and for slideshow)
Microsoft on Wednesday said it will begin offering payments of up to $100,000 for "truly novel exploitation techniques" that defeat security protections in Windows 8.1 Preview, the latest version of the company's popular desktop operating system.

As part of the Microsoft Mitigation Bypass Bounty program, the company is also offering up to $50,000 for defensive strategies that mitigate accepted exploits. Microsoft isn't paying for any old bugs; it is specifically interested in exploits that defeat Windows security technologies such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR).

In addition, during the beta period between June 26 and July 26, Microsoft will pay up to $11,000 for critical vulnerabilities that affect Internet Explorer 11 Preview.

Windows has long been the dominant operating system on personal computers and, as a result, remains a major target for cybercriminals. Over a decade ago, Microsoft began trying to address the concerted assault on its operating system with its Trustworthy Computing initiative, the result of a directive from Bill Gates, then CEO of the company. The company expanded its commitment to security with programs that followed such as Secure Development Lifecycle and the coordination of industry collaboration programs.

[ Are your Dynamics apps on third-party hosts? Read Microsoft Dynamics Apps Hit Azure Cloud. ]

Although Microsoft clearly recognizes the risk and the value of vulnerabilities -- it provides information about flaws to government agencies before releasing that information to the public -- it has only just awoken to the value of recognizing those who find vulnerabilities.

Mozilla has been offering rewards to security researchers who find bugs in its code since 2004. Google launched its Chrome bug bounty program in late 2010 and has since paid out $828,000 to over 250 researchers. Facebook introduced a bug bounty program in July 2011.

Dozens of companies offer rewards or acknowledgements of some sort to those who provide information about security vulnerabilities. But in the past few years, that recognition has not kept pace with the value of exploit information. Google recently increased its rewards, but a Forbes report last year suggests that quality zero-day vulnerabilities can be sold for $250,000 or more.

"I am a little surprised that it took Microsoft this long to create a bug bounty program," said Chris Wysopal, co-founder and CTO of Veracode, in a blog post. "They seem to be jumping in with a second-generation bug bounty program putting the emphasis on exploitation and valuable mitigation techniques. On the open market these techniques could be used to build many zero-day exploits and [could] possibly command more than the Microsoft bounty..."

At the Black Hat USA 2013 conference, scheduled for July 27-Aug. 1, Microsoft plans to invite anyone who wants to participate in its Mitigation Bypass Bounty to do so live before its judging committee in the Black Hat Sponsor Hall. Black Hat is operated by UBM TechWeb, which also owns InformationWeek.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3341
Published: 2014-08-19
The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.

CVE-2014-3464
Published: 2014-08-19
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers ...

CVE-2014-3472
Published: 2014-08-19
The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.

CVE-2014-3490
Published: 2014-08-19
RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have...

CVE-2014-3504
Published: 2014-08-19
The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Dark Reading continuing coverage of the Black Hat 2014 conference brings interviews and commentary to Dark Reading listeners.