Microsoft has launched an initiative offering up to $30,000 to security researchers who identify critical vulnerabilities in its AI-driven platforms, Dynamics 365 and Power Platform. This move underscores Microsoft’s commitment to enhancing the security of its systems by addressing potential manipulation of AI inference or unauthorized information disclosure via model behavior.
In-Depth Look at the Bounty Program
The bug bounty program targets vulnerabilities within Microsoft-hosted services, as well as third-party and open-source components that are integrated into these services. To qualify, researchers must demonstrate a security impact on an eligible service. The maximum payout of $30,000 is reserved for comprehensive reports detailing critical issues like ‘Inference Manipulation’ or ‘Inferential Information Disclosure’.
Other incentives include $20,000 for medium-quality reports and $12,000 for lower quality findings, also involving critical impacts. Reports with important severity can earn between $6,000 and $20,000 based on their quality. However, moderate- and low-severity AI issues do not qualify for this payment tier.
Target Areas and Scope
A wide range of products are eligible for this program, including Dynamics 365 modules such as Sales, Customer Service, and Finance, among others. Additionally, platforms like Power Apps, Power Automate, and AI Builder are covered. The broad scope reflects the platforms’ proximity to crucial business data and automated processes.
Specific areas of focus include critical remote code execution vulnerabilities, cross-tenant information disclosure, and elevation of privilege issues. For these, awards can reach up to $20,000, with additional multipliers for high-impact exploits in Dataverse or Plugin Sandbox environments.
Submission Guidelines and Exclusions
Microsoft has set strict submission criteria, requiring reports to be filed through the MSRC Researcher Portal. Submissions must include detailed reproduction steps, proof-of-concept materials, and an explanation of the potential attacker impact. Findings must be reproducible on the latest, fully patched versions of the relevant products.
Certain vulnerabilities, such as publicly known bugs, denial-of-service attacks, and issues that merely reveal system prompts, are typically excluded from the program. Researchers are advised to test only within authorized environments and halt any investigation if unauthorized data is accessed.
By offering substantial rewards for identifying these vulnerabilities, Microsoft aims to fortify its AI systems against potential security threats, ensuring more robust protection for its users. This initiative not only incentivizes thorough research but also aligns with best practices in coordinated vulnerability disclosure, promoting secure development and deployment of AI technologies.
