Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft paid security researcher Laxman Muthiyah a $50,000 bounty for reporting a password-recovery vulnerability that could potentially have enabled Microsoft account takeover, according to a SecurityWeek report published March 4, 2021. The report says Microsoft patched the issue in November after receiving it the previous year. This is a historical account of a patched flaw; the sources do not establish that it remains exploitable today.

What the reported vulnerability involved

SecurityWeek described a recovery process in which someone entered an email address or phone number, received a security code, and entered that code to continue toward changing the account password. The report says the code had seven digits and Microsoft used attempt limits and IP blocking to hinder automated guessing.

Muthiyah’s reported finding was that sending requests concurrently could evade a defense that would be triggered if requests arrived with even a slight delay. SecurityWeek attributed to him the claim that he submitted around 1,000 seven-digit codes, including the correct one, and reached the next password-change step. He was quoted as saying: “I sent around 1000 seven digit codes including the right one and was able to get the next step to change the password.” These mechanics and figures are the researcher’s account as reported by SecurityWeek, not independently reproduced findings here. Read SecurityWeek’s March 4, 2021 report.

The report also attributed to Muthiyah a claim that the method could bypass an authenticator-app step when two-factor authentication was enabled. He said combining the six-digit and seven-digit code spaces would require around 11 million concurrent request attempts. Those quantities describe the reported research, not a current estimate of exposure or a set of instructions for exploiting accounts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

What Microsoft reportedly did

SecurityWeek said Microsoft received the report in the preceding year and patched the issue in November; it did not identify an exact patch date or patch identifier. The article reported that Microsoft assessed the issue as Important and characterized it as elevation of privilege involving multi-factor authentication bypass.

The article attributed the non-Critical assessment to the attack’s complexity, including the need for substantial computing power and the ability to spoof thousands of IP addresses. That is the reported rationale for this case, not a general rule for how Microsoft rates vulnerabilities.

How the 2021 bounty compares with Microsoft’s published program today

Microsoft’s Identity Bounty page, reviewed October 4, 2026, lists awards from $750 to $100,000 USD and says decisions depend on severity, impact, and report quality. Its general award table lists $50,000 for high-quality Important-severity elevation-of-privilege reports involving authentication plus multi-factor authentication bypass. The matching figure provides context, but does not establish the exact rubric or decision process used for Muthiyah’s 2021 award. A future report with similar characteristics is not guaranteed the same payout.

Reference point Date and scope What is established
Reported case SecurityWeek report published March 4, 2021 SecurityWeek reported a $50,000 award to Muthiyah for the password-recovery flaw and said the issue had been patched in November after a report the preceding year. The article does not give an exact patch date or identifier.
Published program terms Microsoft Identity Bounty page reviewed October 4, 2026 The live page lists $750–$100,000 USD in eligible awards and a general-table $50,000 category for high-quality Important-severity authentication elevation-of-privilege reports involving MFA bypass. These are current published terms, not proof of the 2021 case’s exact evaluation.

For current eligibility, Microsoft says a report must concern a previously unreported critical or important vulnerability with qualifying security impact. Listed qualifying conditions include reproduction in the latest public version of an in-scope identity service, takeover of a Microsoft Account or Azure Active Directory account, or a qualifying issue in an implemented identity standard. Reports should include a description and concise reproduction steps, impact, the attack vector when it is not obvious, and a correlation ID. Microsoft directs submissions through the Microsoft Identity Bounty program page and MSRC Researcher Portal, and reserves the right to accept or reject submissions under its criteria. Check the live page before relying on its scope or award terms, which may change.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why a 2015 promotion does not explain the award

Microsoft’s August 5, 2015 announcement described a temporary doubled-payout period for authentication vulnerabilities running from August 5 through October 5, 2015. That expired promotion predates the 2021 report and should not be confused with either the reported $50,000 award or the current program terms. Microsoft’s 2015 announcement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.