[CRITICAL] "Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers"
criticalDetails
A critical vulnerability was discovered in Microsoft Bing's image search service. By submitting a specially crafted SVG file, an attacker could achieve remote code execution as NT AUTHORITY\SYSTEM on Windows-based image processing servers and as root on Linux machines within the same fleet. The vulnerability resides deep within Bing's image processing tier, affecting multiple hosts and network ranges.
Affected Systems
Microsoft Bing image processing services.
Potential Impact
Compromise of Microsoft's production servers, potentially leading to data breaches, further lateral movement within Microsoft's infrastructure, and a widespread service disruption. The SYSTEM/root level access grants the attacker full control over the affected servers.
Mitigations
Microsoft has issued patches for the associated CVEs (CVE-2026-32194). While this is an internal Microsoft issue, it highlights the risk of vulnerabilities in third-party services. Customers using Bing APIs for image processing should monitor Microsoft's security bulletins for any required actions.