Root cause
Recovery controls did not enforce attempt limits consistently across simultaneous verification operations. Defensive reviews should verify atomic, account-bound limits and consistent treatment of recovery and multifactor checks.
Demonstrated impact
Potential account takeover; the researcher says Microsoft classified severity as Important because practical exploitation required substantial resources.
Lessons for review
- Bind recovery attempts and verification state to the intended account.
- Use atomic security counters and test concurrent state transitions locally.
Award and evidence
Researcher says the bounty was received on February 9, 2021; that is the payment date, not a separately confirmed award-decision date.
Primary public sources read; individual reward, dates, and attribution reviewed. No target testing performed.
- The article header now shows a 2024 update; its archive preserves March 2, 2021 publication
- No independent vendor-hosted payout confirmation retrieved
- Current article update: 2024-12-06; original publication is stored separately.
Recorded timeline
- Published
- 2021-03-02explicit · Original publication date preserved by the author’s archive; current article header is a later update.
- Fixed
- 2020-11explicit
- Paid
- 2021-02-09explicit
Sources and provenance
- Microsoft account recovery lacked consistent attempt-limit enforcement Laxman Muthiyah · reviewed 2026-10-02
- Original publication archive Laxman Muthiyah · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.