Microsoft is looking to head off the next Meltdown or Spectre-like vulnerabilities with a lucrative new bug bounty program. The company announced this week that it will pay up to $250,000 for the discovery of new speculative execution side channel vulnerabilities, the same class of vulnerability that includes the Meltdown and Spectre exploits disclosed in January.
"Speculative execution is truly a new class of vulnerabilities, and we expect that research is already underway exploring new attack methods," says Philip Misner, a security group manager at Microsoft's Security Response Center. "This bounty program is intended as a way to foster that research and the coordinated disclosure of vulnerabilities related to these issues."
The company is offering rewards of varying payouts across four tiers.
- Tier 1: New categories of speculative execution attacks - Up to $250,000
- Tier 2: Azure speculative execution mitigation bypass - Up to $200,000
- Tier 3: Windows speculative execution mitigation bypass - Up to $200,000
- Tier 4: Instance of a known speculative execution vulnerability (such as CVE-2017-5753) in Windows 10 or Microsoft Edge. This vulnerability must enable the disclosure of sensitive information across a trust boundary - Up to $25,000
Given the severity of Meltdown and Spectre, it's not surprising that Microsoft would offer significant bounties for the discovery of related vulnerabilities. The company says that speculative execution side channel vulnerabilities "require an industry response," and that it will share any vulnerabilities disclosed through the program with affected parties so that they can collaborate on a solution.
Microsoft has been active in responding to Meltdown and Spectre, first issuing an emergency Windows update not long after the vulnerabilities were disclosed. Microsoft is now helping to distribute Intel's microcode updates through its update catalog as well. For its part, Intel just announced that it is redesigning its upcoming processors to guard against two of the exploit variants at the hardware level.
We may earn a commission for purchases using our links. Learn more.
Everything Bethesda Softworks is working on right now for Xbox and PC
Microsoft stunned the gaming world when it announced it was acquiring ZeniMax Media, adding Bethesda Softworks to Xbox. Here's everything Bethesda Softworks is working on right now.
We go hands-on with the remastered Age of Empires III: Definitive Edition
Age of Empires III: Definitive Edition is expected to be released October 15, 2020, and we were able to get our hands on a preview build to see how it's coming along.
Dell's XPS 13 2-in-1 and XPS 15 are both beautiful, but which one is best?
These two laptops from Dell are similarly priced, but they have some significant differences that will sway you one way or the other in your buying process. We've laid out the stuff you need to know right here.
These are the best Ethernet switches money can buy
We rounded up a few great examples of managed switches to get you started on creating a solid network at home or in the office. These are great hubs for connecting various devices with some offering speeds of up to 10Gb.