A critical command injection vulnerability in Bing's image processing pipeline allows unauthenticated attackers to execute arbitrary commands as SYSTEM on Microsoft's servers by uploading a crafted SVG file via the 'Search by Image' feature. CVSS 9.8.