logo

Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers

ID: adb42cf6-6edc-5ae3-8ddb-fdde53f32190

STIX ID: report--adb42cf6-6edc-5ae3-8ddb-fdde53f32190

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Guru Baran

...
...

This report details three critical RCE vulnerabilities (two in Bing Images image-processing pipelines exploitable via crafted SVGs and a third involving unrestricted executable uploads) that enabled command execution as NT AUTHORITY\SYSTEM on Bing image-processing workers; the issues were discovered and disclosed by XBOW and have been patched by Microsoft, but the findings warn that similar image converters remain high-risk and require configuration, egress controls, and sandboxing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.