Contents
How are bounty awards determined in Microsoft bounty program?
The products and services in scope for bounty awards and award amounts are published on the Microsoft Bounty Programs pages. Microsoft retains sole discretion in determining which submissions are qualified. If we receive multiple bug reports for the same issue from different parties, the bounty will be awarded to the first eligible submission.
When is a duplicate report eligible for a bounty?
If Microsoft is aware of the issue internally but has not yet released a fix, the first eligible external submission is still eligible for award. If a duplicate report provides new information that was previously unknown to Microsoft, we may award a differential to the person submitting the duplicate report.
What makes you not eligible for Microsoft bounty?
Submissions that do not follow CVD may not be eligible for bounty and could disqualify you from participating in bounty programs in the future. Microsoft will exercise reasonable efforts to clarify indecipherable or incomplete submissions, but more complete submissions are often eligible for higher bounties (see program award tables for details).
What happens when you submit a bounty to MSRC?
You will receive an email confirming that we have received your submission. The MSRC case managers and engineering team will review the submission, including reproducing the vulnerability and assessing the severity and security impact.
How long does it take for a bounty to be awarded?
The bounty period lasts 7 days. Bounties must have a minimum duration of at least 1 day. After the bounty ends, there is a grace period of 24 hours to manually award the bounty.
What do you need to know about a bounty?
If you’ve asked a good question, edited it with status and progress updates, and still are not receiving answers, you can draw attention to your question by placing a bounty on it. A bounty is a special reputation award given to answers. It is funded by the personal reputation of the user who offers it, and is non-refundable.
Can you get a bounty for a vulnerability?
If your vulnerability report affects a product or service that is within scope of one of our bounty programs below, you may receive a bounty award according to the program descriptions. Even if it is not covered under an existing bounty program, we will publicly acknowledge your contributions when we fix the vulnerability.