Microsoft will now pay you up to $40,000 for reporting vulnerabilities in .NET


                            Microsoft Will Now Pay You Up to $40,000 for Reporting Vulnerabilities in .net

Microsoft will now pay you up to $40,000 for reporting vulnerabilities in .NET

Home » News » Microsoft will now pay you up to $40,000 for reporting vulnerabilities in .NET
Table of Contents
microsoft dot net
Picture credit: Microsoft

Many firms provide bug bounty applications as they encourage folks to seek for and uncover safety vulnerabilities in software program, and report them privately to the seller so {that a} repair could be applied and utilized earlier than a malicious actor exploits them. Safety researchers and different members of the general public are financially incentivized to do that as they’re awarded financial rewards. Now, Microsoft has introduced main updates to its .NET Bounty Program.

Rewards now begin from $7,000 and go as much as a mouth-watering $40,000. Remember the fact that highest tier reward is simply relevant to the non-public disclosure of a distant code execution (RCE) or Elevation of Privilege (EoP) vulnerability with full documentation and a vital impression.

The breakdown for the varied rewards tiers is as follows:

Safety Impression Report High quality Vital Essential
Distant Code Execution

Full

$40,000 $30,000
Not Full $20,000 $20,000
Elevation of Privilege Full $40,000 $10,000
Not Full $20,000 $4,000
Safety Characteristic Bypass Full $30,000 $10,000
Not Full $20,000 $4,000
Distant Denial of Service Full $20,000 $10,000
Not Full $15,000 $4,000
Spoofing or Tampering Full $10,000 $5,000
Not Full $7,000 $3,000
Info Disclosure Full $10,000 $5,000
Not Full $7,000 $3,000
Documentation or samples included in documentation are insecure or encourage insecurity and should not described as samples which don’t take safety into consideration Full $10,000 $5,000
Not Full $7,000 $3,000

It is very important word that the .NET Bounty Program primarily revolves round .NET and ASP.NET Core, together with Blazor and Aspire. However new product classes now function all supported variations of .NET and ASP.NET, ASP.NET Core for .NET Framework, the templates supplied with the aforementioned, GitHub Actions of their repositories, and adjoining applied sciences like F#.

The up to date rewards construction ensures that severity ranges are clearly outlined in order that high-impact points generate greater rewards, with tips round how a report could be thought-about “full” too. You’ll find extra data in Microsoft’s devoted weblog publish right here.

author avatar
roosho Senior Engineer (Technical Services)
I am Rakib Raihan RooSho, Jack of all IT Trades. You got it right. Good for nothing. I try a lot of things and fail more than that. That's how I learn. Whenever I succeed, I note that in my cookbook. Eventually, that became my blog. 

share this article.

Enjoying my articles?

Sign up to get new content delivered straight to your inbox.

Please enable JavaScript in your browser to complete this form.
Name