Back to the feed

~/article/bing-images-flaws-let-crafted-svgs-run-commands-as-system-on-microsoft-s-gcbjeo
highSource: The Hacker News

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and

Read at the source

Summary written for cymesh.dev. The full article lives at The Hacker News.

Referenced CVEs

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/bing-images-flaws-let-crafted-svgs-run-commands-as-system-on-microsoft-s-gcbjeo