VeriSign iDefense offers $48,000 for Vista, Internet Explorer 7 vulnerabilities

Share this article:

VeriSign's iDefense Labs is offering a total of $48,000 in awards for remotely exploitable vulnerabilities in the new Windows Vista operating system and Internet Explorer 7.0.

The pot of cash is open to those willing to undertake iDefense Labs' first quarterly vulnerability challenge of 2007. The company explained that it will pay $8,000 for each submitted vulnerability that allows an attacker to remotely exploit and execute code on either of the two Microsoft products. It will award researchers for the first six vulnerabilities submitted that qualify.

In an announcement on the iDefense Labs website, the company said that the challenge is designed to ferret out early weaknesses in both Microsoft releases.

"It is not surprising that the decision to update to the current release of Internet Explorer 7.0 and/or Windows Vista is fraught with uncertainty," read the note. "Primary in the minds of IT security professionals is the question of vulnerabilities that may be present in these two groundbreaking products."

The challenge is open through Mar. 31. In addition to the awards, iDefense Labs said it will also pay a bonus of between $2,000 to $4,000 for code that exploits the submitted vulnerability.

Microsoft has long been a critic of programs, such as iDefense Labs' quarterly challenges, which pay researchers for vulnerabilities.

"Microsoft is aware of iDefense offering compensation for information regarding security vulnerabilities," a company spokesperson told SCMagazine.com today. "Microsoft does not offer compensation for information regarding security vulnerabilities and does not encourage that practice. Microsoft doesn't want to speculate on the motives of third-party researchers but will say that (it) is committed to working with them closely on the issues that they bring to our attention."

The spokesperson went on to say that the company "does not oppose programs that work through the established process for responsible disclosure and do not put customers at risk."

Click here to email West Coast Bureau Chief Ericka Chickowski.

Share this article:

Sign up to our newsletters

More in News

AOL Mail hack furthers spam campaign using spoofed accounts

AOL confirmed on Monday that it was aware of the issue and working to remediate the situation.

Backdoors in Wi-Fi routers, said to be closed, can be reopened

Backdoors in Wi-Fi routers, said to be closed, ...

Although said to be patched, researcher Eloi Vanderbeken discovered during the Easter holiday that backdoors existing in certain wireless routers can be reactivated.

Apple ships Mac OS X updates, fixes several code execution bugs

Apple ships Mac OS X updates, fixes several ...

Among the addressed vulnerabilities, was a bug affecting WindowServer, which could allow an attacker to execute malicious code outside the sandbox.