NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Windows Vista & IE7 Vulnerabilities Cost from $8,000 to $12,000

Prices for working exploit code range from $2,000 to $4,000 dollars

By Marius Oiaga, Technology News Editor

11th of January 2007, 08:33 GMT

Adjust text size:


With Windows and Internet Explorer accounting of the lion's share of the operating system and, respectively, the browser markets, remote arbitrary code execution vulnerabilities in Vista
and IE7 have a high price.

VeriSign's iDefense Labs revealed that it offers from $8,000 to $12,000 for security flaws that allow for remote arbitrary code execution, in the eventuality of a successful exploit, in both Windows Vista and Internet explorer 7, as part of the Q1, 2007 quarterly challenge that has midnight EST on March 31, 2007 as the deadline for the submissions.

"iDefense will pay $8,000 for each submitted vulnerability that allows an attacker to remotely exploit and execute arbitrary code on either of these two products. Only the first submission for a given vulnerability will qualify for the award, and iDefense will award no more than six payments of $8,000. If more than six submissions qualify, the earliest six submissions (based on submission date and time) will receive the award. The iDefense Team at VeriSign will be responsible for making the final determination of whether or not a submission qualifies for the award," revealed iDefense.

Here are the criteria for the Vista and IE7 Vulnerability Challenge:

- The vulnerability must be remotely exploitable and must allow arbitrary code execution in a default installation of one of the technologies listed above;
- The vulnerability must exist in the latest version of the affected technology with all available patches/upgrades applied;
- 'RC' (Release candidate), 'Beta', 'Technology Preview' and similar versions of the listed technologies are not included in this challenge;
- The vulnerability must be original and not previously disclosed either publicly or to the vendor by another party;
- The vulnerability cannot be caused by or require any additional third party software installed on the target system;
- The vulnerability must not require additional social engineering beyond browsing a malicious site.

Additionally, iDefense will pay sums between $2,000 and $4,000 for functional exploit code in concordance with the submitted vulnerabilities.

"The arbitrary code execution must be of an uploaded non-malicious payload. Submission of a malicious payload is grounds for disqualification from this phase of the challenge. The minimum award for a working exploit is $2,000. In addition to the base award, additional amounts up to $4,000 may be awarded based upon: reliability of the exploit, quality of the exploit code, readability of the exploit code and documentation of the exploit code."
Read by 1,425 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.2/5) 10 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Internet Explorer Sinks Under 80%

133 Critical and Important Microsoft Vulnerabilities

PoC Published for Internet Explorer 7 Vulnerability

Internet Explorer 7 - Zero Vulnerabilities

Microsoft Debuts the 2007 Patching Season

Inspect OS and Software Security

Remove the Search Box from Internet Explorer 7

Merry Vista Vulnerability!

Seven December 2006 Security Bulletins

Firefox 2.0 Continues to Grow in the Detriment of IE7

4 January Microsoft Security Bulletins Discontinued

The First Windows Vista Vulnerability

284 Days - The Attack Window of IE in 2006

Adobe Software and DEP Enabled in IE7

$53 Million Revenue for Mozilla

God Save Internet Explorer

The First Update for Internet Explorer 7

The First Internet Explorer 7 Vulnerability

Windows Vista Is Plagued with Vulnerabilities

The Limitations of Extended Validation SSL Certificates

8 Microsoft Security Bulletins in January

Managing Multiple Home Tabs in IE7

Disable Tabbed Browsing in Internet Explorer 7

Windows Live OneCare Released to Manufacturing

Internet Explorer Developer Toolbar Beta 3

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM