Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITYSYSTEM on Microsoft's production image-processing workers, and as root on…
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITYSYSTEM on Microsoft's production image-processing workers, and as root on…
A critical OS command injection vulnerability in Bing's image processing pipeline allows unauthenticated attackers to execute arbitrary commands as SYSTEM by hosting…
XBOW is an autonomous offensive security startup that discovered and responsibly disclosed the critical Bing vulnerabilities CVE-2026-32194 and CVE-2026-32191. CISO Nico Waisman…
An open-source image processing suite used by Bing's pipeline. Its delegate mechanism was exploited to achieve command injection. The article recommends disabling…
Microsoft's search engine, whose image processing pipeline contained critical command injection vulnerabilities allowing SYSTEM-level code execution via crafted SVGs.