AI-For-Beginners/translations/en/SECURITY.md

3.3 KiB

Security

Microsoft prioritizes the security of its software products and services, including all source code repositories managed through our GitHub organizations, such as Microsoft, Azure, DotNet, AspNet, Xamarin, and our GitHub organizations.

If you believe you've identified a security vulnerability in any Microsoft-owned repository that aligns with Microsoft's definition of a security vulnerability, please report it to us using the process outlined below.

Reporting Security Issues

Do not report security vulnerabilities through public GitHub issues.

Instead, report them to the Microsoft Security Response Center (MSRC) at https://msrc.microsoft.com/create-report.

If you'd prefer to submit a report without logging in, you can email secure@microsoft.com. Whenever possible, encrypt your message using our PGP key, which can be downloaded from the Microsoft Security Response Center PGP Key page.

You should receive a response within 24 hours. If you don't, please follow up via email to confirm we received your original message. Additional details are available at microsoft.com/msrc.

Please include the following information (as much as you can provide) to help us better understand the nature and scope of the potential issue:

  • Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
  • Full paths of the source file(s) related to the issue
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration needed to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if available)
  • Impact of the issue, including how an attacker might exploit it

Providing this information will help us process your report more efficiently.

If you're submitting a report for a bug bounty, more detailed reports may result in higher bounty awards. Visit our Microsoft Bug Bounty Program page for more information about our active programs.

Preferred Languages

We prefer all communications to be in English.

Policy

Microsoft adheres to the principles of Coordinated Vulnerability Disclosure.


Disclaimer:
This document has been translated using the AI translation service Co-op Translator. While we aim for accuracy, please note that automated translations may include errors or inaccuracies. The original document in its native language should be regarded as the authoritative source. For critical information, professional human translation is advised. We are not responsible for any misunderstandings or misinterpretations resulting from the use of this translation.