I hate windows, like I'm trying to get off it because of the ads/ragebait news. I hate edge. Microsoft is basically a never buy anymore, but according to this:
Getting a Windows exploit is higher value than any linux exploit. Given how many servers use Linux, it makes me wonder if Linux 0 click are easier than windows.
There are a bunch of counters like 'there are too many distros', or 'a personal computer of a VIP is higher value than some corporations'. But I'm not sure its fair to include your point number 1.
I like to give people credit where its due, I imagine it took lots of work to make windows as secure as it is. (Giving Android OS the most credit for their 2.5M payout)
Linux servers generally aren't being used interactively though and expose a fairly limited attack surface to the internet, and so I feel like the value in Linux server exploits is more in the openssl/Apache/etc vulnerabilities
Linux is the just kernel. Everything else in a distro is software running on top of it. Kernel bugs are generally hard to exploit remotely and typically have to be chained with other exploits. That's why there's so many specific payouts for common enterprise apps. Windows is a complete, highly integrated OS with a wide array of attack vectors baked right into it.
Plus sketchy companies like Zerodium major customers are nation-state actors who are primarily interested in data exfiltration and the application data stores themselves.
But what’s the point ? Most vulnerable Linux servers are hosting blogs or dns servers. They’re only useful to run a crypto miner or host a phishing page, and for that you probably don’t need to go further than exploit a wordpress bug. No need to go for the kernel or even root.
Whereas a desktop often has users on it who enter banking details or corporate login credentials. Much juicier targets.
The payouts are based on what their 'clients' are willing to pay in turn for the exploits. There's just less of a market for Linux kernel exploits. If nation-state actors are involved in deep APT style attacks where they would leverage low level kernel exploits they are going to either develop the exploits themselves or acquire them through their own clandestine channels. Purchasing that stuff from a publicly facing company that could potentially be compromised themselves is high risk and leaves too obvious of a trail.
It's strange to me that Thunderbird is even on their chart. Surely only a few free software enthusiasts use that anymore? Most of the population doesn't even use a desktop email client and if they do its work-provided Outlook to connect to Exchange/Office365.
>Zerodium reviews, tests, validates, and documents all acquired vulnerability research then provides it to institutional clients as part of the
Zerodium only cares about shit their own customers want to target. They aren't trying to fund the entire world of software security.
Their customers in particular are select governments wanting exploits for their own use. You can sure as shit bet they already have specific targets in mind and what they use.
EDIT: For example, the forum software noted on Zerodium's list are popular for "blackhat" and "darkweb" forums from everything from card dump selling to malware. Many governments would love to get themselves a database dump with some user IPs. Conversely, this is why Discourse which is a major BB these days is missing as it's not popular in those circles.
The endless fluff and clutter to clean up (Search bar appearing on desktop, sidebar foistware). The relentless marketing and push of adjacent services (Bing AI).
The passive-aggressive IE compatibility mode (unremovable nag banner to stop using IECM, your Legacy App URLs expire after 30 days for no good reason).
https://zerodium.com/program.html
Getting a Windows exploit is higher value than any linux exploit. Given how many servers use Linux, it makes me wonder if Linux 0 click are easier than windows.
There are a bunch of counters like 'there are too many distros', or 'a personal computer of a VIP is higher value than some corporations'. But I'm not sure its fair to include your point number 1.
I like to give people credit where its due, I imagine it took lots of work to make windows as secure as it is. (Giving Android OS the most credit for their 2.5M payout)