Microsoft is looking to head off the next Meltdown or Spectre-like vulnerabilities with a lucrative new bug bounty program. The company announced this week that it will pay up to $250,000 for the discovery of new speculative execution side channel vulnerabilities, the same class of vulnerability that includes the Meltdown and Spectre exploits disclosed in January.
"Speculative execution is truly a new class of vulnerabilities, and we expect that research is already underway exploring new attack methods," says Philip Misner, a security group manager at Microsoft's Security Response Center. "This bounty program is intended as a way to foster that research and the coordinated disclosure of vulnerabilities related to these issues."
The company is offering rewards of varying payouts across four tiers.
- Tier 1: New categories of speculative execution attacks - Up to $250,000
- Tier 2: Azure speculative execution mitigation bypass - Up to $200,000
- Tier 3: Windows speculative execution mitigation bypass - Up to $200,000
- Tier 4: Instance of a known speculative execution vulnerability (such as CVE-2017-5753) in Windows 10 or Microsoft Edge. This vulnerability must enable the disclosure of sensitive information across a trust boundary - Up to $25,000
Given the severity of Meltdown and Spectre, it's not surprising that Microsoft would offer significant bounties for the discovery of related vulnerabilities. The company says that speculative execution side channel vulnerabilities "require an industry response," and that it will share any vulnerabilities disclosed through the program with affected parties so that they can collaborate on a solution.
Microsoft has been active in responding to Meltdown and Spectre, first issuing an emergency Windows update not long after the vulnerabilities were disclosed. Microsoft is now helping to distribute Intel's microcode updates through its update catalog as well. For its part, Intel just announced that it is redesigning its upcoming processors to guard against two of the exploit variants at the hardware level.
We may earn a commission for purchases using our links. Learn more.

ID@Azure is a new program for indie cloud development, based on ID@Xbox
Microsoft is spinning up a new program aimed at introducing independent devs and teams to Azure cloud-based services and infrastructure, according to this new job listing.

Microsoft is testing 1080p xCloud streams for Xbox Game Pass gaming
Xbox Game Pass Ultimate is currently limited to 720p for streaming to mobile devices, but we've seen evidence that it's about to get bumped up to 1080p. Here's what you need to know.

Here are 10 Xbox games that need 'FPS Boost'
FPS Boost is another impressive feature currently available in the Xbox backwards compatibility utility belt. Here are 10 games we want to see take advantage of enhanced framerates.

Expand your Xbox storage with one of these spectacular SSDs
Chances are you're going to run out of space on your Xbox One. These five leading SSDs pull the best out of your Xbox One.