Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Management & Strategy

Microsoft Offers Up to $30,000 for Vulnerabilities in Teams Desktop Client

Microsoft on Wednesday announced that its bug bounty programs now also cover the desktop client of its Teams business communications platform.

Microsoft on Wednesday announced that its bug bounty programs now also cover the desktop client of its Teams business communications platform.

The tech giant is offering rewards for vulnerabilities in the Teams desktop client as part of its Application Bounty Program, which will feature additional app-related bounties in the future.

The Teams desktop client bug bounty program complements the existing awards for vulnerabilities in online Teams services.

Microsoft says researchers can earn between $500 and $15,000 for general vulnerabilities in the Teams desktop client, and between $6,000 and $30,000 if they demonstrate an exploit that fits one of five scenarios.

For example, white hat hackers can earn up to $30,000 for remote code execution with no user interaction, and $15,000 for the ability to obtain authentication credentials for other users without leveraging phishing attacks.

Payouts for vulnerabilities in Microsoft Teams desktop client

Microsoft reported in August 2020 that it had paid out nearly $14 million through its bug bounty programs in the past year. The single biggest reward was $200,000.

Advertisement. Scroll to continue reading.

Related: Microsoft Launches ElectionGuard Bug Bounty Program

Related: Microsoft Explains How It Processes Vulnerability Reports

Related: Microsoft Offers Up to $30,000 for Flaws in Chromium-Based Edge

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.

Forcepoint has named Proofpoint veteran Vincent Merlin as its new Chief Marketing Officer.

Vensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.