#3
The Hacker News
general
July 24, 2026 at 11:45 UTC
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
By [email protected] (The Hacker News)
AI Summary
XBOW researchers discovered that crafted SVG files submitted to Bing Image Search executed commands as NT AUTHORITY\SYSTEM on Windows and as root on Linux within Microsoft's production image-processing worker fleet, affecting multiple hosts across different network ranges. Microsoft issued two critical CVEs — CVE-2026-32194 and a second unspecified CVE — to address the vulnerabilities. The server-side RCE impact on Microsoft's production infrastructure makes this a significant supply-chain and cloud security incident.
Relevance score: 85.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →