Microsoft Defender launches a new round of vulnerability reward program with a maximum reward of $20000
CTOnews.com, November 23, Microsoft today issued a press release announcing that it will launch a new round of reward program for its Microsoft Defender, mainly encouraging security researchers to find vulnerabilities in the software, with a reward of up to $20000 (CTOnews.com Note: currently about 143000 yuan).
According to Microsoft, Microsoft Defender aims to enhance the security experience of Microsoft customers, and the Microsoft Defender reward program will invite researchers around the world to look for vulnerabilities in the software. The new round of Defender reward program will start with a "limited scope", focusing on Microsoft Defender for Endpoint API, and will be expanded over time to include other Defender products.
According to Microsoft, vulnerabilities submitted by security personnel must pass the following criteria to receive a reward:
Must be newly discovered vulnerabilities that do not include vulnerabilities previously reported to Microsoft
The vulnerabilities are serious and can be reproduced in the latest, fully patched versions of the product or service.
Security personnel should provide reproduction steps that are clear, concise and replicable, in either written or video format.
Microsoft said that depending on the severity of the vulnerability, the price of the reward would range from $500 to $8000 (currently about 3580 to 57280 yuan) for researchers who found vulnerabilities related to remote code execution in Defender. Awards in this category will range from $5000 to $20000 (currently about 35800 to 143000 yuan).