> Sooo, after around 3 months it ended as-is: "Important, Spoofing" and that the desktop client - remote code execution - is "out of scope".
literally unbelievable. wow.
literally unbelievable. wow.
a) Paid out a bonus anyways for the finding (bug bounties do this often, certainly we did at Dropbox)
b) Made this scoping issue more explicit somewhere
Here https://www.microsoft.com/en-us/msrc/bounty-microsoft-cloud is a header "IN-SCOPE DOMAINS AND ENDPOINTS" with alist of domains and that is described with the following: "Only the following domains and endpoints are eligible for bug bounty awards."
I couldn't find something that would match the Teams app on general bug bounty website either (https://www.microsoft.com/de-de/msrc/bounty)