Skip to main content

Make some serious cash finding bugs with Microsoft's Office Insider Bug Bounty program

ubuntu
Image used with permission by copyright holder
There’s probably no better way to find security bugs than to offer money to the people who actually use software on a daily basis to do just that. That’s why companies like Microsoft and Google offer increasingly significant amounts of money through reward programs aimed at discovering and then fixing vulnerabilities.

Microsoft has its lucrative Bug Bounty program for Windows that just saw its reward double to $30,000 for anyone identifying a verified exploit. Now, the company has announced a new program that offers some serious cash to users of its Office productivity suite for Windows Desktop.

The new Office Insider Bug Bounty program will pay anyone using the Insider slow ring builds up to $15,000 for finding security bugs before they have a chance to make their way to the production version. The kinds of bugs for which Microsoft will pay out include:

  • Elevation of privilege via Office Protected View.
  • Macro execution by bypassing security policies to block macros.
  • Code execution by bypassing Outlook automatic attachment block policies.

Go here to dig into the details of how Microsoft will determine eligibility and how you need to submit your bugs. These particular bugs are viewed as likely to be the most prominent and most likely to affect Office users. Macros and email attachments are common vectors of attack on all Office platforms.

Before you spend too much time looking for bugs, here’s a list of vulnerabilities that will not be covered:

  • Vulnerabilities in anything earlier than the current Office Insider slow build on Windows Desktop.
  • Vulnerabilities in user-generated content.
  • Vulnerabilities requiring extensive or unlikely user actions.
  • Vulnerabilities found by disabling existing security features.
  • Vulnerabilities in components not installed by Office.
  • Vulnerabilities in third-party components that might be installed on the system that enable the vulnerability.
  • Vulnerabilities about escaping Protected View where Protected View is explicitly not activated in Office code or enabled by default for the reported scenario.
  • Vulnerabilities in the Application container.
  • Any other category of vulnerability that Microsoft determines to be ineligible, in its sole discretion.

The Microsoft Office Bug Bounty program will last from March 15, 2017, through June 15, 2017. Payouts will range from $500 to $15,000, and of course, there are important terms and conditions to keep in mind. You also need to be a member of the Office Insider program utilizing an Insider slow ring build of Office for Windows Desktop.

You can sign up to be an Office Insider here. Go to File > Account and look under Office Updates to check which version you’re running. Click on Office Insider and select Change Level to move from one ring to another or remove yourself from the Office Insider program.

Editors' Recommendations

Mark Coppock
Mark has been a geek since MS-DOS gave way to Windows and the PalmPilot was a thing. He’s translated his love for…
The 6 best Steam Deck alternatives in 2024
The game library of the Lenovo Legion Go.

Thanks to some great brand recognition and the fact pretty much all PC gamers are tied into the Steam ecosystem anyhow, it makes sense that we all gravitate towards the Steam Deck when it comes to portable gaming with a highly customizable flavor. The relatively recent addition of the Steam Deck OLED has made it even more appealing with great screen quality improving the experience. However, what about if you want to try something other than the Steam Deck? It’s a great portable console but it isn’t perfect and other options may suit your needs better.

To help you figure out what’s best for your needs, we’ve picked out some of the best Steam Deck alternatives currently available. Each system offers a slightly different experience to the Steam Deck while providing the same great game playing experience, across different gaming ecosystems. To help you come to the best decision, we’ve also looked at why we’ve picked the consoles we’ve picked. Read on while we take you through everything you ned to know.
The best Steam Deck alternatives in 2024

Read more
The 6 best detachable laptops in 2024
The Surface Pro 9 with the Type Cover keyboard lifted up.

Detachable laptops – or tablets with removable keyboards – are a popular alternative to traditional laptops. These devices are ultra-portable and versatile, allowing you to stow them in even the most cramped backpack. They also serve as both tablet and laptop, letting you make use of their touchscreen for notetaking or drawing before reattaching their keyboard to type up a lab report or presentation.

There are hundreds of detachable laptops to choose from in 2024, including powerful models from Microsoft, Apple, Dell, and ASUS. However, it can be hard to narrow down all the options, as many of them offer similar specs or identical designs.

Read more
I want to love Asus’ gaming earbuds, but there are problems
The Asus Cetra Supernova earbuds sitting on top of a gaming PC.

I've been warming up to gaming earbuds over the past couple of years. Although one of the best headsets for PC gaming wins in terms of immersion, the low-profile nature of earbuds is better for comfort during long gaming sessions. Asus seems to agree, with its new Cetra True Wireless SuperNova earbuds squarely targeting gamers who value comfort as much as sound quality.

The $200 earbuds sound like the perfect package. You've getting noise cancellation, a low-latency connection, high-fidelity audio, and support for just about any platform imaginable. The package is excellent, and Asus manages fantastic audio quality and comfort while packing in many features. Still, there are a handful of minor issues here that Asus needs to address, especially at the premium price it's asking, which is where my problems lie.
Meet the Cetra True Wireless SuperNova

Read more