Skip to main content

 

Report a Computer Security Vulnerability

The Microsoft Security Response Center investigates all reports of security vulnerabilities affecting Microsoft products and services. If you are a security researcher and believe you have found a Microsoft security vulnerability, we would like to work with you to investigate it.

Please note that the Microsoft Security Response Center does not provide technical support for Microsoft products. If you need assistance with something other than reporting a possible security vulnerability, please see the statement below that most closely matches your situation and expand the statement for next steps.

If you are a security researcher and believe you have found a security vulnerability that meets the definition of a security vulnerability that is not resolved by the 10 Immutable Laws of Security, please send e-mail to us at secure@microsoft.com. To help us to better understand the nature and scope of the possible issue, please include as much of the below information as possible.

  • Type of issue (buffer overflow, SQL injection, cross-site scripting, etc.)
  • Product and version that contains the bug, or URL if for an online service
  • Service packs, security updates, or other updates for the product you have installed
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue on a fresh install
  • Proof-of-concept or exploit code
  • Impact of the issue, including how an attacker could exploit the issue

Microsoft follows Coordinated Vulnerability Disclosure (CVD) and, to protect the ecosystem, we request that those reporting to us do the same.

To encrypt your message to our PGP key, please download it from the Microsoft Security Response Center PGP Key.

You should receive a response within 24 hours. If for some reason you do not, please follow up with us to ensure we received your original message.

For further information, please visit the Microsoft Security Response Policy and Practices page and read the Acknowledgment Policy for Microsoft Security Bulletins.

 

 

If your computer is showing symptoms of spyware, viruses, or other unwanted software, you should first let your antivirus software scan your computer and try to fix the problem.

You should also ensure that your computer has all the latest security updates from Microsoft Update, and that you are getting security updates automatically.

If you continue to have trouble, you can find additional support options by visiting the Virus and Security Solution Center.

 

 

If you’re having issues with Microsoft security updates, you can visit the Microsoft Support site to find fixes for Windows Update issues, or contact Microsoft customer support.

If you need technical information about security updates, please refer to the Security Update Guide, where you can search for information about a specific update or filter by release date and/or product range.

 

 

To find the appropriate support information for your location, visit Microsoft Product Support Services.

See the Forums home page on TechNet to browse questions and answers, or ask your own question.

 

 

Cybercriminals often use phishing email messages to try to steal personal information. Learn how to recognize what a phishing email message looks like and how to avoid scams that use the Microsoft name fraudulently.

To learn about the latest scams, browse through the Security Tips & Talk blog posts.

If you think you’ve been the victim of a scam, find out how you can report it and protect yourself in the future.

 

 

Please send your virus, worm, or trojan horse submission to avsubmit@submit.microsoft.com. Send your spyware or other malware submission to windefend@submit.microsoft.com.

 

 

Please submit your thoughts at Contact Us: Questions About Microsoft Products.