Payout for Zero-Click Outlook Zero-Days has been increased to $400,000 by Zerodium.
It was announced on the same day that Trustwave SpiderLabs revealed a new approach to get around Outlook security and send malicious links to victims. was reported by threatpost.
Zerodium, an exploit acquisition platform, has temporarily boosted its prize for zero-click remote code executions in Microsoft Outlook from $250,000 to $400,000. These vulnerabilities can attack a target without the user having to do anything, such as read an email or open an attachment. Government entities especially in North America and Europe are Zerodium’s customers.
“We are temporarily increasing our payout for Microsoft Outlook RCEs from $250,000 to $400,000. We are looking for zero-click exploits leading to remote code execution when receiving/downloading emails in Outlook, without requiring any user interaction such as reading the malicious email message or opening an attachment. Exploits relying on opening/reading an email may be acquired for a lower reward.” –Zerodium
https://twitter.com/Zerodium/status/1486762616101945357
The reward for Microsoft Outlook zero-click remote code executions (RCEs) has been doubled from $250,000 to $400,000. Zerodium, an exploit acquisition platform, has boosted its payout for Microsoft Outlook zero-click remote code executions (RCEs) from $250,000 to $400,000. The increase is a temporary tactic to achieve zero-click attacks, which can attack computers and networks without the need for human input. On its page for limited-time bug bounties, Zerodium explains the change.
Some assaults, such as phishing scams, necessitate user interaction, such as opening an email or email attachment. Because zero-click attacks don’t require user engagement, they’re more harmful.
Zerodium is a security firm that focuses on zero-day exploits and research. Its clients are mostly government agencies in North America and Europe.
The higher compensation for Microsoft Outlook zero-click RCEs started on January 27, 2022, although there is no set end date yet.
Trustwave talks of CVE-2020-0696 bypasses. Links using URI schemes will trigger a warning box, and ”:/” characters will be removed when transmitted to users, according to the CVE-2020-0696 fix. However, that change did not completely resolve the initial problem, and I later discovered a workaround.
The patch will strip ”:/ ” from the link and transmit it to the user as “http://maliciouslink,” circumventing Microsoft ATP Safelink and other Email security programs, with the new exploit vector “http:/://maliciouslink.”
When the victim hits the link, it is automatically changed to http://maliciouslink and opened. This flaw can be used to compromise Outlook clients on both Windows and Mac OS X.
Experienced cybersecurity journalist tracking active ransomware outbreaks, regulatory compliance shifts (GDPR/CCPA), and global corporate data breach remediations.
Security Digest
Get the latest cybersecurity news, vulnerability alerts, and threat intelligence delivered to your inbox.
Related Articles
Pakistan-Linked APT36 Exploits "Pahalgam Terror Attack" Theme in Multi-Pronged Cyber Espionage Campaign Against India
In a recent and concerning development in the ongoing cyber conflict landscape, the Pakistan-linked Advanced Persistent Threat (APT) group known as APT36 (also referred to as Transparent Tribe) has...
Threat IntelligenceNATO Examines Data Breach from Missile Vendor on the Dark Web
One set of documents purportedly belonging to an EU defense supplier includes information on the weapons Ukraine used to fight Russia. According to a report in the media, NATO is looking into the l...
Threat IntelligenceIndian Organizations also targetted by Bvp47 backdoor of US NSA Equation Group
Banaras Hindu University, India Education Network, Eureka Technology Partners, Indian Academy of Sciences, Indian Institute of Tropical Meteorology, Council of Scientific & Industrial Research (CSIR)
Threat IntelligenceFree Cybersecurity Services And Tools Released by CISA
CISA has collected a list of free cybersecurity tools and services to help companies advance their security capabilities as part of our ongoing objective to minimise cybersecurity risk among U.S. c...