Microsoft Outlook RCE Vulnerability Can Sell For $400,000
Zerodium has just announced that they have increased the price of the zero-day vulnerability that allows remote code execution (RCE) on Microsoft Outlook to $ 400,000 (equivalent to VND 9 billion). Zerodium is an American security company that specializes in acquiring zero-day vulnerabilities for research purposes and then reporting and recommending solutions to firms.
Zerodium did not disclose the end date of this purchase price increase, but shared that it will only be applied in the short term.
Zero-click mining
Normally, Zerodium will spend $250,000 for an RCE vulnerability in the Microsoft Outlook for Windows client. The minimum requirement is that the vulnerability has a well-functioning, fully functional, and reliable exploit method.
However, when the price was raised to $400,000, Zerodium required the vulnerability to be exploited to execute code remotely without any interaction from the victim, aka zero-click. The extraction takes place while Outlook is receiving and downloading the email.
"We are temporarily increasing the payout for RCE vulnerabilities in Microsoft Outlook from $250,000 to $400,000. We're looking for a zero-click exploit that leads to remote code execution when receiving/downloading emails. in Outlook without any user interaction such as reading malicious emails or opening attachments," shared Zerodium.
Of course, vulnerabilities that can be exploited by tricking users into reading malicious emails or opening attachments will still be recognized by Zerodium. However, the amount received will be under $400,000.
If you are a security expert and have a Microsoft Outlook RCE vulnerability, do not hesitate to contact Zerodium immediately.
You should read it
- Microsoft expert discovered a series of serious code execution errors in IoT, OT devices
- The Mail app on iOS has serious vulnerabilities
- Microsoft rewards $ 250,000 for any talent that discovers the new Meltdown and Specter vulnerabilities
- Detects 'long-standing' security vulnerabilities in Microsoft Office
- New dangerous vulnerability in Intel CPU: Works like Specter and Meltdown, threatening all PCs and the cloud
- HP publishes a series of critical vulnerabilities in the Teradici PCoIP protocol
- 5 common errors in managing security vulnerabilities
- Security vulnerabilities - basic insights
- Release software to check DNS server vulnerabilities
- EternalRocks - more dangerous malicious code than WannaCry exploits up to seven NSA vulnerabilities
- How to check if the computer has serious Windows 10 vulnerabilities
- Microsoft patched 6 zero-day vulnerabilities in Windows 10