ZeroHour
Cyber Security Newspublished ()ingested Guru Baran

Microsoft Offers Up to $30,000 for Critical AI Flaws in Dynamics 365 and Power Platform

infoIndustryimportance 25
AI summary · glm-5.3

Microsoft expands AI bug bounty to Dynamics 365 and Power Platform, paying up to $30,000 for critical inference manipulation flaws.

Microsoft's bug bounty program offers up to $30,000 for critical 'Inference Manipulation' or 'Inferential Information Disclosure' bugs in Dynamics 365 and Power Platform, including Copilot Studio, AI Builder, Power Apps, Power Automate, and Dataverse. Payouts scale by report quality ($30,000/$20,000/$12,000 for critical) with important-severity AI flaws earning $6,000-$20,000, plus 20% multipliers for Dataverse privilege escalation and Plugin Sandbox escapes. Prompt injection affecting only the attacker, hallucinated execution, and system-prompt disclosure are excluded from scope.

  • Maximum $30,000 for critical inference manipulation or information disclosure flaws
  • Scope covers Dynamics 365, Power Apps, Power Automate, Copilot Studio, AI Builder, Dataverse
  • 20% multiplier for Dataverse privilege escalation and Plugin Sandbox escapes
  • Self-affecting prompt injection and content-safety issues excluded
Full article629 words · extracted from cybersecuritynews.com · click to collapse

Microsoft is offering security researchers up to $30,000 for finding critical AI vulnerabilities in Dynamics 365 and Power Platform, sharpening its focus on flaws that could manipulate AI inference or expose information through model behavior.

The program covers qualifying bugs in Microsoft-hosted services and third-party or open-source components embedded in them, provided researchers demonstrate a security impact on an in-scope service.

Under the bounty table, a high-quality report documenting critical “Inference Manipulation” or “Inferential Information Disclosure” can earn the maximum $30,000.

Medium- and low-quality reports for critical impacts are listed at $20,000 and $12,000, while important-severity findings can receive between $6,000 and $20,000 depending on report quality. Moderate- and low-severity AI submissions do not qualify for payment under this category.

The scope is broad because these platforms sit close to sensitive business data and automated workflows.

Eligible targets include Dynamics 365 Sales, Customer Service, Finance, Commerce, Human Resources, Business Central, Contact Center, Customer Insights and Supply Chain Management, alongside on-premises Dynamics products. It also covers Power Apps, Power Automate, Copilot Studio, Power Pages, Power Admin, AI Builder, and Dataverse.

Vulnerability Category / Focus AreaImpact Severity & Quality TierMaximum Payout / MultiplierScope & Qualification Details
Inference Manipulation & DisclosureCritical (High / Med / Low Quality)$30,000 / $20,000 / $12,000Manipulates model responses or extracts data via model behavior
Important AI VulnerabilitiesImportant (High / Med / Low Quality)$20,000 / $12,000 / $6,000High-impact functional or security flaws across AI integrations
Remote Code Execution (RCE)Critical SeverityUp to $20,000Code execution flaws across in-scope cloud and service components
Cross-Tenant Information DisclosureHigh-Impact ScenarioUp to $20,000Breaches tenant boundaries to access external organization data
Elevation of Privilege / Info DisclosureCritical SeverityUp to $12,000Local and cloud-level unauthorized privilege escalation
Dataverse & Sandbox EscapesSpecial High-Impact Vectors+20% MultiplierDataverse privilege escalation & Plugin Sandbox host escapes

Microsoft requires AI findings to meet its Critical or Important severity definitions and reproduce on the latest, fully patched version of an eligible product.

Researchers must submit reports through the MSRC Researcher Portal and provide the Power Platform or Dynamics environment ID, the username used during testing, and whether the bug matches a high-impact scenario.

Clear reproduction steps, proof-of-concept material, affected versions, and an explanation of attacker impact can accelerate validation and support a higher award.

Beyond AI payouts, the bug bounty program assigns up to $20,000 for critical remote code execution, $12,000 for critical elevation-of-privilege or information-disclosure flaws, and $8,000 for critical spoofing or tampering reports.

Cross-tenant information disclosure carries a $20,000 high-impact award, while qualifying Dataverse privilege escalation and Plugin Sandbox “guest-to-host” escapes can receive a 20% multiplier. A report eligible for multiple awards receives only the highest qualifying payment, although Microsoft may grant more at its discretion.

The program distinguishes exploitable AI security failures from model quirks. Prompt injection affecting only the attacker, hallucinated code execution, attempts merely to reveal a system or meta prompt, and content-safety issues are excluded.

Publicly known bugs, denial-of-service attacks, blind cross-site scripting, dependency confusion, and configuration-dependent weaknesses are also generally out of scope.

Researchers should test only in accounts and tenants they own or are authorized to assess, stop immediately if unauthorized data becomes accessible, and avoid post-exploitation, lateral movement, phishing, or disruptive traffic.

Microsoft recommends marking research tenants with “MSOBB” where possible and following coordinated vulnerability disclosure, ensuring findings reach engineers without exposing customers or production services to risk.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/microsoft-ai-bug-bounty/