Como denuncio vulnerabilidades no Windows?

0

Eu tenho procurado por vulnerabilidades no Windows 8 e no Windows 7 e gostaria de relatá-las à Microsoft.

Alguns são extremamente importantes, incluindo um que compromete o armazenamento de chaves do usuário sem solicitar a senha do administrador.

Como posso relatar essas vulnerabilidades à Microsoft?

    
por DividedByZero 30.10.2014 / 20:31

1 resposta

6

Em Relate uma vulnerabilidade de segurança do computador :

If you are a security researcher and believe you have found a security vulnerability that meets the definition of a security vulnerability that is not resolved by the 10 Immutable Laws of Security, please send e-mail to us at [email protected] with as much of the below information as possible. This information will help us to better understand the nature and scope of the possible issue.

  • Type of issue (buffer overflow, SQL injection, cross-site scripting, etc.)
  • Product and version that contains the bug
  • Service packs, security updates, or other updates for the product you have installed
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue on a fresh install
  • Proof-of-concept or exploit code
  • Impact of the issue, including how an attacker could exploit the issue
    
por 30.10.2014 / 21:06