This is beyond believe: a RCE classified as "Spoofing".
This is beyond believe: a RCE classified as "Spoofing".
So that is basically a giant middle finger to the security researchers.
Source: https://www.microsoft.com/en-us/msrc/bounty-microsoft-cloud
I think bounties are an unbalanced system; as you say, pentesters don’t get paid for their time and often don’t get paid at all, like in this case. There must be a better way, where an independent third-party can judge actual severity of the hole and sanction payments.
MSFT has a market cap of $1.62T. A quick Google says "The median net worth of the average U.S. household is $97,300." That works out to 0.1¢.
I work at a BigCo as a recipient of some of these XSSs and I'm awed by the amount of work that goes into them. I always try to overstate the impact to boost the reward- it's not just the bug that they found, but how much of the system they had to look at before they found this. The security folks at BigCo that I interact with are badasses, but it's just so hard to get this level of attention.
To prevent the appeals process being abused, the appellant should have to pay for the time spent by the independent researchers verifying their complaint. For a successful appeal, the company offering the bounty should have to pay that extra cost, encouraging them not to be stingy with the awards they give out in the first place.
The truth is that the exploit acquisition market has many legal issues. Zerodium, who is often thought to be the leading buyer, publishes misleading guides and has had unusual timing in between the initial disclosure and hacking attempts on the researcher themselves. Other buyers have non-negotiable sale (not license!) contracts that may result in your zeroday being misused, and you may find yourself in a conspiracy. And those are the reputable and responsible buyers, there are others outside the US that are fronts for Israel/UAE/China. The market has plenty of room for correction, but there's a shortage of ethical buyers.
If you could easily sell an exploit outside of a bug bounty program for more money, you'd see more people doing it regardless of the ethics (see: the NSA doing a bulk of the hiring in infosec, noone I spoke with that applied cared about the illegal surveillance disclosures and said they chose it because they offered 100k+). So the researchers currently have no choice, and the bounty programs take advantage of that. When the pendulum swings the other direction, you'll see bounty programs becoming more fair/lucrative.
I wonder whom you'd consider an ethical buyer apart from the software maker for a closed source software since no one else can realistically patch it?
So there isn't much choice here
To be fair the impact on the desktop app is higher since it also has access to the OS and the attacker is not stuck inside the browser sandbox. But from my understanding it still is possible to steal the SSO token. When i think about O365 setups with OneDrive for Business and Sharepoint that means the attacker would have access to all files stored there. That usually means all company related files that person has. Additionally the attacker would have access to all emails and messages of the user.
How is that not critical?
And according to the Bug Bounty side, Spoofing bugs "do not qualify for this severity category".
Isn't that precisely what spoofing is?
The thing is that according to Microsoft critical spoofing is not possible.
Not in my opinion. I’ve always thought of spoofing as a write only type thing where you can impersonate someone, but not have access to any of their existing data. Email spoofing is a good example of this.
Token theft is WAY more severe because it gives you complete access to everything. It’s total control. You can exfiltrate data and that’s what I’d consider the biggest difference, at least in my opinion.
The technicality is still absurd and beyond belief, but I'd say the responsibility for that absurdity falls with company policy, not with the MS security staffer's classification.
I mean, do you look at that demo and think "yeah, that's technically just 'important' let's fix it in 2 months"?
I got one automated email from them since, that's all.
I don't expect to get paid, I was just curious to see what the "process" is, and how they treat security vulnerability reports.
The verdict: Badly.