Microsoft will increase the payout for certain bugs by $400,000 for a limited time

Reading time icon 2 min. read


Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team Read more

Key notes

  • Microsoft will pay out a maximum of $400,000 for bugs in Outlook, although the company has not disclosed how long that bounty program will be available.
  • Zerodium, an exploit acquisition platform, has increased its bounty for zero-click remote code execution in Microsoft Outlook from $250,000 to $400,000.
  • Zerodium's customers are primarily government agencies in North America and Europe.

Exploit acquisition platform Zerodium has increased its payout for zero-click RCEs in Microsoft Outlook from $250,000 to $400,000.

Zero-click exploits let attackers compromise PCs and networks without requiring user interaction. One company that buys such exploits, Zerodium, outlines the change on its limited-time bug bounties page.

Set off the exploit

Some cyberattacks, such as phishing emails or instant messages, require people to interact with an attack in order to set off the exploit. Zero-click exploits do not require interaction, making them even more dangerous.

“We are temporarily increasing our payout for Microsoft Outlook RCEs from $250,000 to $400,000,” indicated Zerodium. “We are looking for zero-click exploits leading to remote code execution when receiving/downloading emails in Outlook, without requiring any user interaction such as reading the malicious email message or opening an attachment. Exploits relying on opening/reading an email may be acquired for a lower reward.”

Zerodium is a security company specializing in acquiring and reselling zero-day exploits and vulnerabilities. Its primary customers are government agencies in North America and Europe.

Increased payout

Microsoft increased the payout for Outlook zero-click RCEs on January 27, 2022. They will continue until a date undisclosed.

Microsoft offers bounties from $5,000 to $250,000 for reports of vulnerabilities in its software. The company paid $13.6 million for bug bounty rewards between July 2020 and July 2021.

Microsoft’s bug bounty payout is less than that of Zerodium; the bounty values vary based on the severity of the discovered vulnerability.

What is your take on Microsoft’s way around the bugs? Share your thoughts with us in the comment section below.

User forum

0 messages