Vulnerabilities / Threats
6/19/2013
03:31 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Microsoft Dangles $100,000 Bug Bounty

One hitch: The bugs might be worth more on the open market.

Google Apps To Microsoft Office 365: 10 Lessons
Google Apps To Microsoft Office 365: 10 Lessons
(click image for larger view and for slideshow)
Microsoft on Wednesday said it will begin offering payments of up to $100,000 for "truly novel exploitation techniques" that defeat security protections in Windows 8.1 Preview, the latest version of the company's popular desktop operating system.

As part of the Microsoft Mitigation Bypass Bounty program, the company is also offering up to $50,000 for defensive strategies that mitigate accepted exploits. Microsoft isn't paying for any old bugs; it is specifically interested in exploits that defeat Windows security technologies such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR).

In addition, during the beta period between June 26 and July 26, Microsoft will pay up to $11,000 for critical vulnerabilities that affect Internet Explorer 11 Preview.

Windows has long been the dominant operating system on personal computers and, as a result, remains a major target for cybercriminals. Over a decade ago, Microsoft began trying to address the concerted assault on its operating system with its Trustworthy Computing initiative, the result of a directive from Bill Gates, then CEO of the company. The company expanded its commitment to security with programs that followed such as Secure Development Lifecycle and the coordination of industry collaboration programs.

[ Are your Dynamics apps on third-party hosts? Read Microsoft Dynamics Apps Hit Azure Cloud. ]

Although Microsoft clearly recognizes the risk and the value of vulnerabilities -- it provides information about flaws to government agencies before releasing that information to the public -- it has only just awoken to the value of recognizing those who find vulnerabilities.

Mozilla has been offering rewards to security researchers who find bugs in its code since 2004. Google launched its Chrome bug bounty program in late 2010 and has since paid out $828,000 to over 250 researchers. Facebook introduced a bug bounty program in July 2011.

Dozens of companies offer rewards or acknowledgements of some sort to those who provide information about security vulnerabilities. But in the past few years, that recognition has not kept pace with the value of exploit information. Google recently increased its rewards, but a Forbes report last year suggests that quality zero-day vulnerabilities can be sold for $250,000 or more.

"I am a little surprised that it took Microsoft this long to create a bug bounty program," said Chris Wysopal, co-founder and CTO of Veracode, in a blog post. "They seem to be jumping in with a second-generation bug bounty program putting the emphasis on exploitation and valuable mitigation techniques. On the open market these techniques could be used to build many zero-day exploits and [could] possibly command more than the Microsoft bounty..."

At the Black Hat USA 2013 conference, scheduled for July 27-Aug. 1, Microsoft plans to invite anyone who wants to participate in its Mitigation Bypass Bounty to do so live before its judging committee in the Black Hat Sponsor Hall. Black Hat is operated by UBM TechWeb, which also owns InformationWeek.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2382
Published: 2014-11-20
The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to cause a denial of service (crash) and execute arbitrary code via a crafted IOCTL request that writes to arbitrary memory locations, related to the IofCallDriver function.

CVE-2014-3625
Published: 2014-11-20
Directory traversal vulnerability in Pivitol Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVE-2014-8387
Published: 2014-11-20
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

CVE-2014-8493
Published: 2014-11-20
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.

CVE-2014-8767
Published: 2014-11-20
Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of service (crash) via a crafted length value in an OLSR frame.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?