Skip to main content

Microsoft’s bug bounty system now offers up to $15,000 for finding Windows flaws

Typing on a MacBook.
Fabian Irsara/Unsplash
Microsoft has expanded its existing bug bounty system to include all manner of Windows flaws if they are found within one of its slow ring Insider builds. Whether you find them in the base operating system itself, or any of its companion software pieces, you may now be able to claim a finder’s fee reward from Microsoft up to $15,000, Ars Technica reports

Bug bounty systems are a tried-and-tested formula for finding bugs before they can see wider exploitation. It turns the practice of discovering flaws into a money-making endeavor, rather than the exploitation of them. Microsoft has seen much success with bounties for the Edge browser, and exploit-mitigation systems.

Recommended Videos

It’s now added an ongoing bounty offering of up to $15,000 for “critical and important vulnerabilities” discovered in the slow ring Windows Insider preview builds. This represents the most general bounty scheme that Microsoft has yet launched and opens the door to a wider range of exploits to be discovered.

As much as digging for bugs in Windows Insider builds would be a decent way to earn a living for a number of hackers, regardless of the color hat they wear, Microsoft’s older, more selective bounty systems are still far more lucrative. One key area Microsoft is looking to shore up is its virtual machine Hyper-V system. Find a flaw in that and Microsoft could reward you up to $250,000, whether it is for Windows 10, Server 2012 or a Windows Server Insider preview.

Problems found with the Windows Defender Application Guard come with a $30,000 bounty attached, whereas mitigation bypass bugs could net you as much as $100,000 if discovered. In total there are eight ongoing bug bounty schemes, some of which have been in operation for as long as four years.

The reward figures listed are the maximum, however, so most bugs will unlikely earn that much. The smallest payout for any category is $500, so don’t expect to retire if you find a singular flaw in a piece of Microsoft software. The potential is there, though, if your detection skills are strong enough.

You have time to find them too, as most crucially, the new bounties are not time-limited. While in the past the software giant often pushed for bugs to be found within a select time period to help clear up software before launch, with its new bounties it has them all listed as “ongoing,” with no stated plan for finalizing them.

Jon Martindale
Jon Martindale is a freelance evergreen writer and occasional section coordinator, covering how to guides, best-of lists, and…
Brace yourself for PC hardware to get insanely expensive next year
The Hyte Y40 PC case sitting on a table.

None of us like higher prices, but that's exactly what we could be in for next year.

I'm going to be analyzing the impact of Donald Trump's proposed tariffs on the price of PC hardware in the future, using not only some estimates that are available now, but also the historical context of tariffs during Trump's first administration. My point is not to say anything political in nature, but instead to take a serious look at just how much these tariffs will affect PC hardware pricing.

Read more
5 calendar apps you should use instead of Outlook
A man using Google Calendar on a laptop.

Microsoft has just redesigned its Outlook email app, and it’s fair to say that the change has made some people unhappy. But Outlook covers more than just email -- it’s got a built-in calendar too, and Microsoft’s plan is to ditch the existing Mail and Calendar apps for Windows and merge them both into Outlook. That means that anyone switching away from the email app also needs a new way to manage their schedule.

That’s where our guide comes in. We’ve found five of the best Outlook alternatives you can get your hands on, and they run the gamut of features and philosophies, from privacy-minded options to those that are built for productivity. Whatever you need, chances are you’ll find it below.
Notion Calendar

Read more
MacBook Pro M4 teardown shows a repairability rut for Apple laptops
The MacBook Pro 16-inch on a table.

The updated slate of MacBook Pros, powered by the M4 series silicon, has once again established Apple’s performance dominance in the segment. However, a teardown courtesy of the folks over at iFixit has confirmed that not much has changed internally, which means the usual repairability snags are still here.

Starting with the new elements this time around, Apple engineers seem to have redesigned the logic board, increasing the heatsink size and shifting a few component locations. The ports are easy to replace on the new laptop, and the battery is repair-friendly as well.

Read more