Vulnerabilities / Threats
6/19/2013
03:31 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Microsoft Dangles $100,000 Bug Bounty

One hitch: The bugs might be worth more on the open market.

Google Apps To Microsoft Office 365: 10 Lessons
Google Apps To Microsoft Office 365: 10 Lessons
(click image for larger view and for slideshow)
Microsoft on Wednesday said it will begin offering payments of up to $100,000 for "truly novel exploitation techniques" that defeat security protections in Windows 8.1 Preview, the latest version of the company's popular desktop operating system.

As part of the Microsoft Mitigation Bypass Bounty program, the company is also offering up to $50,000 for defensive strategies that mitigate accepted exploits. Microsoft isn't paying for any old bugs; it is specifically interested in exploits that defeat Windows security technologies such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR).

In addition, during the beta period between June 26 and July 26, Microsoft will pay up to $11,000 for critical vulnerabilities that affect Internet Explorer 11 Preview.

Windows has long been the dominant operating system on personal computers and, as a result, remains a major target for cybercriminals. Over a decade ago, Microsoft began trying to address the concerted assault on its operating system with its Trustworthy Computing initiative, the result of a directive from Bill Gates, then CEO of the company. The company expanded its commitment to security with programs that followed such as Secure Development Lifecycle and the coordination of industry collaboration programs.

[ Are your Dynamics apps on third-party hosts? Read Microsoft Dynamics Apps Hit Azure Cloud. ]

Although Microsoft clearly recognizes the risk and the value of vulnerabilities -- it provides information about flaws to government agencies before releasing that information to the public -- it has only just awoken to the value of recognizing those who find vulnerabilities.

Mozilla has been offering rewards to security researchers who find bugs in its code since 2004. Google launched its Chrome bug bounty program in late 2010 and has since paid out $828,000 to over 250 researchers. Facebook introduced a bug bounty program in July 2011.

Dozens of companies offer rewards or acknowledgements of some sort to those who provide information about security vulnerabilities. But in the past few years, that recognition has not kept pace with the value of exploit information. Google recently increased its rewards, but a Forbes report last year suggests that quality zero-day vulnerabilities can be sold for $250,000 or more.

"I am a little surprised that it took Microsoft this long to create a bug bounty program," said Chris Wysopal, co-founder and CTO of Veracode, in a blog post. "They seem to be jumping in with a second-generation bug bounty program putting the emphasis on exploitation and valuable mitigation techniques. On the open market these techniques could be used to build many zero-day exploits and [could] possibly command more than the Microsoft bounty..."

At the Black Hat USA 2013 conference, scheduled for July 27-Aug. 1, Microsoft plans to invite anyone who wants to participate in its Mitigation Bypass Bounty to do so live before its judging committee in the Black Hat Sponsor Hall. Black Hat is operated by UBM TechWeb, which also owns InformationWeek.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1544
Published: 2014-07-23
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger cer...

CVE-2014-1547
Published: 2014-07-23
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2014-1548
Published: 2014-07-23
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2014-1549
Published: 2014-07-23
The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbird before 31.0 does not properly allocate Web Audio buffer memory, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and applica...

CVE-2014-1550
Published: 2014-07-23
Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging incorrect Web Audio control-message ordering.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Sara Peters hosts a conversation on Botnets and those who fight them.