VeriSign iDefense offers $48,000 for Vista, Internet Explorer 7 vulnerabilities

Share this article:

VeriSign's iDefense Labs is offering a total of $48,000 in awards for remotely exploitable vulnerabilities in the new Windows Vista operating system and Internet Explorer 7.0.

The pot of cash is open to those willing to undertake iDefense Labs' first quarterly vulnerability challenge of 2007. The company explained that it will pay $8,000 for each submitted vulnerability that allows an attacker to remotely exploit and execute code on either of the two Microsoft products. It will award researchers for the first six vulnerabilities submitted that qualify.

In an announcement on the iDefense Labs website, the company said that the challenge is designed to ferret out early weaknesses in both Microsoft releases.

"It is not surprising that the decision to update to the current release of Internet Explorer 7.0 and/or Windows Vista is fraught with uncertainty," read the note. "Primary in the minds of IT security professionals is the question of vulnerabilities that may be present in these two groundbreaking products."

The challenge is open through Mar. 31. In addition to the awards, iDefense Labs said it will also pay a bonus of between $2,000 to $4,000 for code that exploits the submitted vulnerability.

Microsoft has long been a critic of programs, such as iDefense Labs' quarterly challenges, which pay researchers for vulnerabilities.

"Microsoft is aware of iDefense offering compensation for information regarding security vulnerabilities," a company spokesperson told SCMagazine.com today. "Microsoft does not offer compensation for information regarding security vulnerabilities and does not encourage that practice. Microsoft doesn't want to speculate on the motives of third-party researchers but will say that (it) is committed to working with them closely on the issues that they bring to our attention."

The spokesperson went on to say that the company "does not oppose programs that work through the established process for responsible disclosure and do not put customers at risk."

Click here to email West Coast Bureau Chief Ericka Chickowski.

Share this article:

Sign up to our newsletters

More in News

Firefox 32 feature could cut undetected malware downloads 'in half'

Mozilla plans to introduce a feature in Firefox 32 that, based on preliminary testing, could cut the amount of undetected malware downloads in half.

EFF asks court to find NSA internet spying a violation of Fourth Amendment

EFF asks court to find NSA internet spying ...

Complete with a colorful graphic, the EFF showed a federal court how the NSA essentially runs a digital dragnet that can pick up innocent Americans.

Study: Asian Android users at higher risk of malware exposure

Cheetah Mobile's new study showed that Asian Android users have a two to three times greater risk of downloading malware onto their devices.