Microsoft has announced that it is increasing rewards for serious vulnerabilities (those with significant impact) reported through the bug bounty programs Microsoft 365 and Dynamics 365/Power Platform
With the addition of scenario-based bounty awards to these two programs, security researchers who report vulnerabilities in Office 365 and Microsoft Account can earn much higher rewards than before (up to a 30% increase).
See also: Microsoft takes control of ZLoader botnet infrastructure

“Through these new scenario-based bounty awards, we encourage researchers to focus their research on vulnerabilities that have the highest potential impact on customer privacy and security,” a statement from the Microsoft Security Response Center (MSRC) revealed.
“Prizes increase by up to 30% ($26,000 USD total) for eligible script submissions“.
However, Microsoft added that bugs with lower impact may still be eligible for rewards under the General Awards program.
They could also receive higher rewards based on the severity of the reported vulnerability and the quality of the submissions.
“If a reported vulnerability does not qualify for a bounty award under the High Impact Scenarios, it may be eligible for a bounty award under the General Awards,” the company specifically says.
Microsoft bug bounty
| Scenario | Maximum Award |
| Remote code execution through untrusted input (CWE-94 “Improper Control of Generation of Code ('Code Injection')”) | 30.00% |
| Remote code execution through untrusted input (CWE-502 “Deserialization of Untrusted Data”) | 30.00% |
| Unauthorized Cross-tenant and cross-identity sensitive data1 leakage (CWE-200 “Exposure of Sensitive Information to an Unauthorized Actor”) | 20.00% |
| Unauthorized cross-identity sensitive data leakage (CWE-488 “Exposure of Data Element to Wrong Session”) | 20.00% |
| “Confused deputy” vulnerabilities that can be used in a practical attack that accesses resources in a way that bypasses authentication (CWE-918 “Server-Side Request Forgery (SSRF)”) | 15.00% |
A few days ago, Microsoft announced that it had added Exchange, SharePoint, and Skype for Business to its bug bounty programs. Security researchers will now be able to identify and report vulnerabilities affecting Exchange servers and SharePoint to earn rewards ranging from $500 to $26,000.
See also: Microsoft: Windows Server supports automatic .NET updates
Rewards in a Microsoft (and other companies) bug bounty program are calculated primarily based on the severity of the reported vulnerabilities.
More details about rewards, high-impact scenarios, and the updated list of in-scope domains are available on the M365 Bounty Program page.

Bug Bounty Programs
Bug Bounty programs offer sums of money so that researchers from different parts of the world can discover and report vulnerabilities and weaknesses they identify in a company's systems before they are discovered and exploited by malicious users.
See also: Microsoft: Windows Autopatch will be released soon
Essentially, a bug bounty is a monetary reward given to so-called “ethical hackers” to use their knowledge and skills to protect an organization. The idea is very clever, since in reality, companies use hackers to deal with other hackers.
More and more companies are launching their own bug bounty programs to protect their products, as malicious users and cybercriminals are constantly looking for vulnerabilities that allow them to carry out attacks.
Source: Bleeping Computer
