If you are a security researcher and believe you have found a security vulnerability that meets the
definition of a security vulnerability that is not resolved by the
10 Immutable Laws of Security, please send e-mail to us at
[email protected]. To help us to better understand the nature and scope of the possible issue, please include as much of the below information as possible.
- Type of issue (buffer overflow, SQL injection, cross-site scripting, etc.)
- Product and version that contains the bug, or URL if for an online service
- Service packs, security updates, or other updates for the product you have installed
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue on a fresh install
- Proof-of-concept or exploit code
- Impact of the issue, including how an attacker could exploit the issue
Microsoft follows
Coordinated Vulnerability Disclosure (CVD) and, to protect the ecosystem, we request that those reporting to us do the same.
To encrypt your message to our PGP key, please download it from the
Microsoft Security Response Center PGP Key.
You should receive a response within 24 hours. If for some reason you do not, please follow up with us to ensure we received your original message.
For further information, please visit the Microsoft Security Response Policy and Practices page and read the
Acknowledgment Policy for Microsoft Security Bulletins.