我刚刚发现一个与 excel 有关的漏洞,该漏洞允许使用 word 文档执行任意代码。问题是如何报告该漏洞,他们是否有可能对其进行修补?
答案1
发送电子邮件到[电子邮件保护]。
您需要包含的信息如下(来自https://www.microsoft.com/en-us/msrc/faqs-report-an-issue?rtc=1)
Type of issue (buffer overflow, SQL injection, cross-site scripting, etc.)
Product and version that contains the bug, or URL if for an online service
Service packs, security updates, or other updates for the product you have installed
Any special configuration required to reproduce the issue
Step-by-step instructions to reproduce the issue on a fresh install
Proof-of-concept or exploit code
Impact of the issue, including how an attacker could exploit the issue