Microsoft Outlook RCE Vulnerability Can Sell For $400,000
Zerodium has just announced that they have increased the price of the zero-day vulnerability that allows remote code execution (RCE) on Microsoft Outlook to $ 400,000 (equivalent to VND 9 billion). Zerodium is an American security company that specializes in acquiring zero-day vulnerabilities for research purposes and then reporting and recommending solutions to firms.
Zerodium did not disclose the end date of this purchase price increase, but shared that it will only be applied in the short term.
Zero-click mining
Normally, Zerodium will spend $250,000 for an RCE vulnerability in the Microsoft Outlook for Windows client. The minimum requirement is that the vulnerability has a well-functioning, fully functional, and reliable exploit method.
However, when the price was raised to $400,000, Zerodium required the vulnerability to be exploited to execute code remotely without any interaction from the victim, aka zero-click. The extraction takes place while Outlook is receiving and downloading the email.
"We are temporarily increasing the payout for RCE vulnerabilities in Microsoft Outlook from $250,000 to $400,000. We're looking for a zero-click exploit that leads to remote code execution when receiving/downloading emails. in Outlook without any user interaction such as reading malicious emails or opening attachments," shared Zerodium.
Of course, vulnerabilities that can be exploited by tricking users into reading malicious emails or opening attachments will still be recognized by Zerodium. However, the amount received will be under $400,000.
If you are a security expert and have a Microsoft Outlook RCE vulnerability, do not hesitate to contact Zerodium immediately.
You should read it
- Microsoft rewards $ 250,000 for any talent that discovers the new Meltdown and Specter vulnerabilities
- Detects 'long-standing' security vulnerabilities in Microsoft Office
- New dangerous vulnerability in Intel CPU: Works like Specter and Meltdown, threatening all PCs and the cloud
- HP publishes a series of critical vulnerabilities in the Teradici PCoIP protocol
- 5 common errors in managing security vulnerabilities
- Security vulnerabilities - basic insights
- Release software to check DNS server vulnerabilities
- EternalRocks - more dangerous malicious code than WannaCry exploits up to seven NSA vulnerabilities
May be interested
- Microsoft Outlook acceleration tipsone of the habits of outlook users is storing too many emails. although emails you don't use, don't open them, outlook still loads these emails. this is the reason why outlook is slow.
- Error cannot open Outlook, this is a fixduring the use of outlook, users often encounter a number of errors. the most basic error is that it cannot open outlook: cannot start microsoft outlook. không mở được outlook outlook. thiết lập của các gói không thể mở lỗi hành động
- The best options replace Microsoft Outlookwithin the scope of email application, microsoft outlook is one of the most commonly used services today. however, the most popular does not mean that it is the best software. there are still some email services for customers with similar functions, even better than microsoft outlook.
- Microsoft brings Outlook Web App to some Android devicesmicrosoft just launched outlook web app (owa) last thursday. this is a web-based application with completely similar features for ios version.
- Detected a serious zero-day vulnerability in Microsoft Office, click the document file and it will stickthe newly discovered vulnerability is called follina and currently there is no official patch from microsoft.
- How to use the Outlook.com Beta versionmicrosoft has officially released a beta test of outlook.com to users around the world with many features to change and update new features.
- Microsoft wants users to switch to the new Outlook before August, or receiving emails will be interruptedthe new outlook for windows app is essentially built on the outlook.com web app.
- Microsoft Outlook Windows is about to receive 'biggest changes' since 1997since 2019, microsoft has attracted a lot of attention when announcing that it will accelerate the rollout of outlook for windows updates with some major improvements.
- Microsoft plans to 'migrate' to the new Outlookmicrosoft has been publicly testing the redesigned outlook windows application for over a year now, and now is probably the time when this project is entering its final stages of completion.
- New points on Microsoft Outlook.com Beta and how to registermicrosoft has started launching the beta version of outlook.com from today. this is the opt-in web version that is enabled on outlook.com and is available to all users in the next few weeks.