By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Bing Images SVG Flaw Allowed System Command Execution

A critical security vulnerability discovered in Microsoft's Bing image search allowed attackers to execute arbitrary commands with SYSTEM privileges on the company's servers. The flaw, identified by security researcher XBOW, was triggered by submitting a specially crafted Scalable Vector Graphics (SVG) file to the image search engine. XBOW's testing confirmed that the vulnerability affected image-processing workers across different hosts and network ranges, indicating a systemic issue within Bing's image tier rather than an isolated incident.
When a malicious SVG was processed, it could execute commands as NT AUTHORITY\SYSTEM on the Windows-based production image-processing workers. Furthermore, on the Linux machines within the same fleet, the crafted SVG could execute commands with root privileges. This level of access on Microsoft's servers poses a significant security risk, potentially allowing for data exfiltration, system compromise, or the deployment of further malicious activities.
Microsoft has acknowledged the severity of the vulnerability and has issued two critical Common Vulnerabilities and Exposures (CVE) advisories. The company assigned CVE-2026-32194 and another unnamed CVE to this specific flaw. The disclosure of these CVEs indicates that Microsoft has developed and deployed patches to mitigate the risk, although specific details regarding the patches or the timeline of their deployment were not immediately available in the initial report. The discovery highlights the ongoing challenges in securing complex web services that process user-submitted content.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.