Microsoft takes the security of our software products and services seriously. This commitment extends to all source code repositories managed through our GitHub organizations, including:
If you believe you have discovered a security vulnerability in any Microsoft-owned repository that meets Microsoft's definition of a security vulnerability, please report it to us following the guidelines below.
Important: Please do not report security vulnerabilities through public GitHub issues.
-
Submit your report to the Microsoft Security Response Center (MSRC):
- Preferred method: https://msrc.microsoft.com/create-report
- Alternative method (if you prefer not to log in): Send email to secure@microsoft.com
-
For encrypted communication: Consider encrypting your message with our PGP key, available from the Microsoft Security Response Center PGP Key page.
-
Response timeline: You should receive a response within 24 hours. If you don't, please send a follow-up email to ensure we received your original message.
-
Additional information: For more details on the reporting process, visit microsoft.com/msrc.
To help us quickly assess the issue, please include as much of the following information as possible:
Information Type | Details to Provide |
---|---|
Issue type | Buffer overflow, SQL injection, cross-site scripting, etc. |
Source files | Full paths of source file(s) related to the issue |
Location | Tag/branch/commit or direct URL to affected code |
Configuration | Any special configuration required to reproduce the issue |
Reproduction steps | Step-by-step instructions to reproduce the issue |
Proof of concept | Exploit code or demonstration (if possible) |
Impact assessment | How an attacker might exploit the issue and potential impact |
Providing thorough information helps us evaluate your report more efficiently.
Bug Bounty Programs: If you're reporting for a bug bounty, more complete reports can contribute to a higher bounty award. For details about our active programs, visit the Microsoft Bug Bounty Program page.
We prefer all communications to be in English.
Microsoft follows the principle of Coordinated Vulnerability Disclosure.