Microsoft Offers $60,000 Bounty for Critical Cross-Tenant Vulnerabilities
Microsoft expands Dynamics 365 and Power Platform bug bounty, paying up to $60,000 for critical cross-tenant vulnerabilities.
Microsoft expanded its bounty incentives for Dynamics 365 and Power Platform, with qualifying rewards from $1,250 to $60,000. Critical cross-tenant vulnerabilities receive a 100% award multiplier and important ones 50%, while critical AI inference manipulation or inferential disclosure can earn up to $30,000. Scope covers Dynamics 365 apps, Power Apps, Power Automate, Copilot Studio, Power Pages, Dataverse, and selected on-premises products. Reports must be rated Critical or Important and submitted via the MSRC Researcher Portal.
- Rewards range $1,250-$60,000; critical cross-tenant flaws get 100% multiplier.
- AI inference manipulation and inferential disclosure findings pay up to $30,000.
- Scope covers Dynamics 365 apps, Power Platform services, and Dataverse.
- Prompt injection without security impact, hallucinations, and DoS excluded.
Full article480 words · extracted from gbhackers.com · click to collapse
Microsoft has expanded its incentives for security researchers focusing on Dynamics 365 and Power Platform, offering rewards ranging from $1,250 to $60,000 for qualifying vulnerabilities.
The program prioritizes flaws that have a direct and demonstrable security impact in supported cloud services, including cross-tenant issues that could compromise isolation between customer environments.
Microsoft Offers $60,000 Bounty
Cross-tenant vulnerabilities are especially critical in multi-tenant enterprise platforms, as they may allow an attacker operating within one organization’s environment to access data, resources, or functions belonging to another organization.
Microsoft designates critical cross-tenant vulnerabilities as a high-impact scenario eligible for a 100% award multiplier. In comparison, important cross-tenant issues receive a 50% multiplier.
The scope of the program includes online Dynamics 365 applications such as Sales, Customer Service, Finance, Supply Chain Management, Business Central, Commerce, and Customer Insights.
It also encompasses Power Apps, Power Automate, Microsoft Copilot Studio, Power Pages, Power Admin, AI Builder, and Dataverse, along with selected on-premises Dynamics products.
| Bounty area | Reward or multiplier |
|---|---|
| Overall qualifying reward range | $1,250 to $60,000 |
| Critical cross-tenant vulnerability | +100% |
| Important cross-tenant vulnerability | +50% |
| Privilege escalation into Dataverse through another Power Platform entry point | +20% |
| Dataverse Plugin Sandbox “guest-to-host” escape | +20% |
| Critical AI inference manipulation or inferential information disclosure | Up to $30,000 |
| Critical unsafe deserialization or code injection | Up to $20,000 |
Researchers must test the latest fully patched version of an in-scope product or service, and reports must be rated either Critical or Important to qualify under the program’s criteria.
Submissions should be made through the MSRC Researcher Portal and include the affected Power or Dynamics environment ID, the testing account username, reproducible evidence, and any applicable high-impact scenario.
Microsoft’s AI bounty categories cover issues related to inference manipulation and inferential information disclosure. A critical finding with a significant security impact and a high-quality report could earn up to $30,000.
However, the company does not accept AI prompt injection findings without security impact beyond the attacker, model hallucinations, attempts to disclose system prompts, or content-related AI issues for bounty eligibility under this program.
The general awards chart lists deserialization of untrusted data and code injection among the highest-paying technical bug classes, with maximum payouts of $20,000.
Authentication flaws, information disclosure, SQL or command injection, SSRF, and improper access control can receive up to $12,000 for critical, high-impact submissions.
Microsoft also excludes vulnerabilities found in unpatched versions, user-created applications or content, customer-controlled misconfigurations, denial-of-service attacks, cookie replay, subdomain takeovers, and blind XSS from typical bounty awards.
Researchers are advised to use test tenants when possible, follow Microsoft’s Rules of Engagement, and avoid impacting customer data, privacy, or service availability.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/microsoft-offers-60000-bounty/