When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

$400,000 payout for Microsoft Outlook zero-click RCE security flaw announced by Zerodium

Microsoft Outlook

Zerodium, a security exploit vendor announced earlier today that it is increasing its prize payout for Microsoft Outlook zero-click remote code executions (RCEs) to $400,000 up from the earlier payout of $250,000, a 60% raise.

Zero-click exploits are especially dangerous as they do not require user interaction if at all, to deliver malicious payloads onto a potential victim's device. Zerodium however has noted that the increase in the payout is "temporary" implying that the decision may be revised later.

Here's the full announcement:

We are temporarily increasing our payout for Microsoft Outlook RCEs from $250,000 to $400,000. We are looking for zero-click exploits leading to remote code execution when receiving/downloading emails in Outlook, without requiring any user interaction such as reading the malicious email message or opening an attachment. Exploits relying on opening/reading an email may be acquired for a lower reward.

In related Outlook news, Microsoft's One Outlook Project Monarch is apparently delayed but it's still making headway according to reports.

Alongside the Microsoft Outlook payout announcement, Zerodium also made an announcement for Mozilla's Thunderbird platform too, with an award bounty of $200,000.

We are looking for zero-click exploits affecting Thunderbird and leading to remote code execution when receiving/downloading emails, without requiring any user interaction such as reading the malicious email message or opening an attachment. Exploits relying on opening/reading an email may be acquired for a lower reward.

More information may be found on the official announcement page.

Report a problem with article
beats solo3 wireless headphones
Next Article

The Beats Solo3 wireless on-ear headphones are discounted by 33% today

Azure fluent design logo
Previous Article

Microsoft sets a new record as it mitigates a 3.47 Tbps DDoS attack on Azure servers

Join the conversation!

Login or Sign Up to read and post a comment.

1 Comment - Add comment