logo

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

ID: 3a28092a-9038-50c1-90a1-347ab948aa7a

STIX ID: report--3a28092a-9038-50c1-90a1-347ab948aa7a

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: [email protected] (The Hacker News)

...
...

XBOW discovered and reported two critical ImageMagick-related command-injection vulnerabilities in Bing's image-processing workers (CVE-2026-32194 and CVE-2026-32191, CVSS 9.8) allowing crafted SVGs to execute shell commands as SYSTEM/root; Microsoft fixed the server-side issues before public disclosure. The report details how SVG references reached a delegate that invoked a shell, outlines proof-of-concept behavior, and recommends mitigations: deny delegates in policy.xml, restrict accepted formats (SVG/MVG/EPS), sandbox and drop privileges for converters, and block or allowlist outbound network access from workers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.