Skip to main content

Microsoft paid out two huge bounties for the same bug in its June patch

posted onJuly 3, 2016
by l33tdawg

The same bug that earned one researcher $50,000 from Microsoft also earned another researcher $100,000.

Tencent researcher Yang Yu, the finder of the so-called BadTunnel bug that Microsoft patched last month wasn’t the only one rewarded for reporting the issue. Moritz Jodeit, a researcher with German security firm, Blue Frost Security, picked up $100,000.

BadTunnel was notable since it affected every version of Microsoft's operating system back to Windows 95. But while Yu's find had a wide impact, Jodeit used the same bug to to bypass many of the latest technologies Microsoft employs to prevent exploits from working,which could also have implications for its latest and most secure browser, Edge for Windows 10. Jodeit has previously sketched a rough outline of the bug and confirmed he had received the highest reward available under Microsoft’s Mitigation Bypass Bounty. However, he drew attention to the bug in a tweet today since it was recently confirmed he will present his work at the Hack in the Box conference in Singapore this August.

Source

Tags

Microsoft

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th