Microsoft paid out two huge bounties for the same bug in its June patch
The same bug that earned one researcher $50,000 from Microsoft also earned another researcher $100,000.
Tencent researcher Yang Yu, the finder of the so-called BadTunnel bug that Microsoft patched last month wasn’t the only one rewarded for reporting the issue. Moritz Jodeit, a researcher with German security firm, Blue Frost Security, picked up $100,000.
BadTunnel was notable since it affected every version of Microsoft's operating system back to Windows 95. But while Yu's find had a wide impact, Jodeit used the same bug to to bypass many of the latest technologies Microsoft employs to prevent exploits from working,which could also have implications for its latest and most secure browser, Edge for Windows 10. Jodeit has previously sketched a rough outline of the bug and confirmed he had received the highest reward available under Microsoft’s Mitigation Bypass Bounty. However, he drew attention to the bug in a tweet today since it was recently confirmed he will present his work at the Hack in the Box conference in Singapore this August.