Connect with us

Cybersecurity

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

Published

on

Security researchers have disclosed two critical vulnerabilities in Microsoft Bing Images that allowed specially crafted SVG (Scalable Vector Graphics) files to execute system-level commands on Microsoft’s production image-processing servers.

The flaws, discovered by autonomous security company XBOW, have already been patched by Microsoft. The company confirmed that the issues were resolved on the server side before public disclosure, meaning no action is required from Bing users.

Two Critical Vulnerabilities Identified

Microsoft assigned the vulnerabilities the following identifiers:

  • CVE-2026-32194 – Command Injection
  • CVE-2026-32191 – Operating System Command Injection

Both flaws received a CVSS severity score of 9.8, highlighting the high risk they posed before remediation.

According to Microsoft’s security advisories, there is no evidence that either vulnerability was exploited in real-world attacks before the fixes were deployed.

Crafted SVG Files Triggered Remote Command Execution

XBOW researchers discovered that Bing’s image-processing infrastructure incorrectly treated portions of specially crafted SVG image files as executable commands rather than simple image data.

By exploiting this behavior, researchers successfully executed benign system commands on Microsoft’s production servers.

Testing showed that commands executed with extremely high privileges:

  • NT AUTHORITY\SYSTEM on Windows servers
  • Root privileges on Linux systems

The consistent results across multiple servers confirmed that the issue affected Bing’s image-processing infrastructure rather than a single misconfigured machine.

Two Separate Attack Paths

Researchers identified two independent methods of reaching the vulnerable image-processing pipeline.

The first vulnerability involved Bing’s Search by Image upload feature, where attackers could upload a malicious SVG file directly through the image submission interface.

The second affected Bing’s image crawler. In this scenario, attackers only needed to host a malicious SVG file online and provide its URL to Bing’s image search service. Bing’s automated crawler would then retrieve the file and process it through the same vulnerable image conversion system.

Neither attack required authentication, user interaction, or existing access to Microsoft systems.

Image Processing Pipeline at the Center of the Issue

According to XBOW, the vulnerability stemmed from the way Bing processed SVG files.

Unlike traditional image formats, SVG files are XML-based and can reference external resources. During image conversion, Bing’s backend relied on image-processing components that delegated certain operations to external programs.

Researchers found that a specially crafted image reference within an SVG could cause the underlying conversion process to interpret attacker-controlled input as a shell command instead of a file path.

This allowed arbitrary operating system commands to execute during image processing.

No Customer Data Accessed

XBOW emphasized that its testing was conducted responsibly.

Researchers limited their activities to harmless, read-only system commands used solely to verify successful code execution. They stated that no customer information was accessed, modified, or exposed during testing.

Microsoft addressed both vulnerabilities before the research was publicly released, following responsible disclosure.

Lessons for Organizations Using Image Processing Software

Although the vulnerabilities specifically affected Microsoft’s Bing infrastructure, researchers noted that similar risks may exist in other applications that process user-supplied images using tools such as ImageMagick or compatible image conversion libraries.

Improperly configured image-processing systems can expose dangerous functionality capable of executing external programs when handling complex file formats like SVG.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO