hacker-news · Crawled Jul 24, 2026

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Read original article ↗

AI Summary

A security researcher from XBOW discovered two critical vulnerabilities in Microsoft's Bing Images service that allowed remote command execution as SYSTEM on Windows and root on Linux servers by exploiting crafted SVG files. The flaws, tracked as CVE-2026-32194 and CVE-2026-32191, stemmed from improper handling of SVG image references that led to command injection via ImageMagick delegates. Microsoft patched the issues server-side before public disclosure, with no evidence of exploitation in the wild.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.