Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
ID: 3a28092a-9038-50c1-90a1-347ab948aa7a
STIX ID: report--3a28092a-9038-50c1-90a1-347ab948aa7a
Feed Name: The Hacker News
XBOW discovered and reported two critical ImageMagick-related command-injection vulnerabilities in Bing's image-processing workers (CVE-2026-32194 and CVE-2026-32191, CVSS 9.8) allowing crafted SVGs to execute shell commands as SYSTEM/root; Microsoft fixed the server-side issues before public disclosure. The report details how SVG references reached a delegate that invoked a shell, outlines proof-of-concept behavior, and recommends mitigations: deny delegates in policy.xml, restrict accepted formats (SVG/MVG/EPS), sandbox and drop privileges for converters, and block or allowlist outbound network access from workers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
