| PREDICTIONS | CURRENT VALUE | TODAY |
| Remote code execution in IE7 | $43.05/ $0.00 | (closed) |
| Remote code execution in Vista | $43.54/ $0.00 | (closed) |
| Remote code execution in MS Office | $41.10/ $0.00 | (closed) |
| Remote code execution in Outlook | $40.14/ $0.00 | (closed) |
| Remote code execution in WMP 10 | $15.19/ $0.00 | (closed) |
for news
Outlook is part of the Office product line. If a vulnerability is discovered in Outlook, will it trigger this market to close as well?
—Erek
You’re right, and I should have structured this better (and made it Office except for Outlook). Because of my mistake, an Outlook exploit in March 2007 will count as both Outlook at Office.
This market looks at several scenarios for Microsoft product security in March, 2007, looking at IE7, Vista, Office, and other products and remote code execution vulnerabilities. Decisions will be based on CVE vectors and Microsoft product bulletins.
At least one remote code execution vulnerability will be disclosed in March, 2007 for the Microsoft product Internet Explorer 7. This vulnerability MAY involve user interaction but MUST allow for arbitrary code execution of the attacker’s choice.
At least one remote code execution vulnerability will be disclosed in March, 2007 for the Microsoft product Windows Vista (excluding additional products such as MS Office). This vulnerability MAY NOT involve user interaction and MUST allow for arbitrary code execution of the attacker’s choice.
At least one remote code execution vulnerability will be disclosed in March, 2007 for the Microsoft product Office. This vulnerability MAY involve user interaction but MUST allow for arbitrary code execution of the attacker’s choice.
At least one remote code execution vulnerability will be disclosed in March, 2007 for the Microsoft products Outlook or Outlook Express. This vulnerability MAY involve user interaction but MUST allow for arbitrary code execution of the attacker’s choice.
At least one remote code execution vulnerability will be disclosed in March, 2007 for the Microsoft product Windows Media Player 10. This vulnerability MAY involve user interaction but MUST allow for arbitrary code execution of the attacker’s choice.