HomeSecurityMicrosoft: Up to $370,000 for Azure Sphere vulnerability reports

Microsoft: Up to $370,000 for Azure Sphere vulnerability reports

Microsoft has awarded over $370,000 in bug bounties to security researchers for vulnerability reports submitted through the Azure Sphere Security Research Challenge (ASSRC) IoT-focused research program. The Azure Sphere Security Research Challenge is a 3-month extension of the Azure Security Lab bounty program that Microsoft announced at Black Hat 2019.

The ASSRC expansion added to the already existing incentives, coordination framework, and support resources to make Coordinated Vulnerability Disclosure (CVD) easier for researchers and further encourage Azure Sphere research.

Microsoft: Up to $370,000 for Azure Sphere vulnerability reports

As BleepingComputer reports, 70 researchers from more than 20 countries submitted 40 vulnerability reports from June 1, 2020, to August 31, 2020, with 30 of these reports leading to improvements to the Azure Sphere IoT security solution

Microsoft has awarded money as a reward to researchers who were able to demonstrate their ability to execute code in the Secure World of the Azure Sphere application platform or in the Microsoft Pluton security subsystem.

Azure Sphere

Additionally, the tech giant said that many of the vulnerabilities identified during the research challenge were novel and high-impact, leading to significant security improvements for Azure Sphere in 20.07, 20.08, and the latest updates , which have been automatically pushed to devices connected to the Internet, to safeguard Azure Sphere customers and expand Microsoft's partnerships with the global IoT security research community.

The company also added that security researchers from McAfee ATR and Cisco Talos reported some of the highest-impact vulnerabilities in Azure Sphere, including a full-scale attack developed by McAfee ATR that exposed a vulnerability in the cloud and multiple vulnerabilities on the device, including a previously unknown vulnerability in the Linux.

Microsoft: Up to $370,000 for Azure Sphere vulnerability reports

Researchers participating in the challenge achieved three of the general scenarios focused on various layers of the Azure Sphere operating system:

  • Anything that allows unsigned code that is not pure ROP (Return Oriented Programming) under Linux.
  • Anything that allows privilege escalation outside of the capabilities described in the application declaration (e.g. changing user ID, adding access to binary).
  • Ability to modify software and configuration options (except for a full device reset) on a device in manufacturing mode.

Researchers can also submit reports of any high-impact vulnerabilities in Azure Sphere as part of the Microsoft Azure bounty program, with the best reports eligible for prizes of up to $40,000.

Microsoft announced in August that it has awarded $13.7 million to researchers who reported vulnerabilities in the past 12 months through 15 bug bounty programs, between July 1, 2019, and June 30, 2020. In 2020 alone, the company ran six new bug bounty programs and two new research grants, receiving 1,226 vulnerability reports from 327 security researchers. Finally, Microsoft also joined the Open Source Security Foundation (OpenSSF) as a founding member in August, along with GitHub, Google, IBM, JPMC, NCC Group, OWASP Foundation, and Red Hat.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS