Microsoft paid out $13.6 million this year through its bug bounty program, a nearly identical sum to last year’s $13.7 million payout.

The software giant released its annual bug bounty review just days after disclosing a critical Windows bug dubbed PrintNightmare. 

Microsoft’s bug bounty program offers security researchers sizable sums of money to find and report vulnerabilities in software before malicious hackers find and exploit those weak points.

Some 341 security researchers across 58 countries worked with Microsoft’s bug bounty program between July 1, 2020 and June 30, 2021. Of the $13.6 million awarded, the largest single award totaled $200,000, and the average award hovered around $10,000. 

As exploits increase in severity, more companies including Google and Intel now offer rewards for vulnerability disclosures.

“We realize that security is a critical part of any user’s decision to use an open-source tool, so we dedicate resources to help ensure we’re providing the best possible security,” explained Maya Kaczorowski, product manager for container security at Google Cloud, in a blog post. 

The bug bounty review comes as Microsoft struggles to patch PrintNightmare, its latest Windows vulnerability, which affects the Windows Print Spooler and allows multiple users to access a connected printer. Through this vulnerability, hackers can view or delete data, install programs, or create new user accounts. Windows 7 and Windows 10 were both affected by this bug, and Microsoft recommended that its users install an out-of-band security update to avoid attacks.

Although Microsoft claims this patch will fix the PrintNightmare vulnerability, some security researchers disagree. Matthew Hickey, co-founder of Hacker House, and Will Dormann, vulnerability analyst, argued that Microsoft’s patch only addresses the remote code execution (RCE) portion of the vulnerability. Attackers are still able to use the local privilege escalation (LPE) component to access system privileges if the Point and Print policy is enabled, they say.

PrintNightmare follows several other critcal Windows bugs. Last month alone the company issued patches for six zero-day vulnerabilities already being exploited by attackers, which reflects the importance of bug bounty programs for maintaining customers’ security.