Virtual Event Today: Ransomware Resilience & Recovery Summit - Login to Live Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Microsoft Expands Bug Bounty Program

Microsoft Offers Up to $15,000 in Bounties for .NET Core, ASP.NET RC2 Beta Vulnerabilities

Microsoft this week announced an expansion to its bug bounty program to include the newly released .NET Core and ASP.NET Core RC2 Beta.

Microsoft Offers Up to $15,000 in Bounties for .NET Core, ASP.NET RC2 Beta Vulnerabilities

Microsoft this week announced an expansion to its bug bounty program to include the newly released .NET Core and ASP.NET Core RC2 Beta.

The expansion serves a simple, forward purpose: the company is getting ready for the final release of .NET Core and ASP.NET and wants to make sure that it squashes security vulnerabilities in the product before that happens. The .NET Core and ASP.NET Core RC2 Beta Build was released in mid-May and researchers can grab it from Microsoft’s website.

By adding the product to the bounty program, the technology giant is looking to receive feedback from the security research community on it, and is also willing to pay for that. In fact, the company has announced that the bounties could go for as much as $15,000. The payouts, however, are dependent on the quality and complexity of the reported vulnerability, and their lower limit has been set at $500.

Between October 2015 and January 2016, Microsoft ran a CoreCLR and ASP.NET 5 Beta bounty program, which was also focused on finding and resolving security issues in the .NET core runtime. The newly revealed bounty extension is a successor of the previous program, and the bounties are similar.

Microsoft also notes that the new program is applicable to .NET Core, ASP.NET Core RC2 and to all of the subsequent Release Candidates that will be released during the bounty period. The final RTM version is also included, provided that it is released within the bounty period, the company explains on the Microsoft Bounty Programs web page.

According to Microsoft, researchers willing to participate in the program can submit reports for vulnerabilities found in .NET Core and ASP.NET Core RC2 on Windows, OS X and Linux platforms.

“This new bounty will be in addition to our ongoing Nano Server beta, Online Services, and Mitigation bypass and Bounty for Defense bounty programs. These additions are a part of the rigorous security programs at Microsoft. Bounties will be worked alongside the Security Development Lifecycle (SDL), Operational Security Assurance (OSA) framework, regular penetration testing of our products and services, and Security and Compliance Accreditations by third party audits,” Microsoft says.

Advertisement. Scroll to continue reading.

Over the past year, Microsoft made various changes to its bug bounty program, starting with the introduction of double payouts for anti-exploitation techniques in August last year. This year, the company expanded the Online Services Bug Bounty to include OneDrive, and also added Nano Server to the Bug Bounty Program in early May.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.