Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Overview
A recent security flaw in Bing's image processing system allowed crafted SVG files to execute commands with elevated privileges, specifically as NT AUTHORITY\SYSTEM on Windows servers and as root on Linux machines. This vulnerability was identified through testing by security researchers at XBOW, who found that the issue was not isolated to a single machine but was present across multiple hosts and network ranges within Bing’s infrastructure. Microsoft responded by issuing two critical CVEs, CVE-2026-32194 and another unnamed one, to address the vulnerabilities. This incident raises significant concerns about the security of cloud-based services and the potential for attackers to exploit similar flaws to gain unauthorized access to sensitive systems. Companies relying on these services should prioritize patching and review their security protocols to mitigate risks from this kind of vulnerability.
Key Takeaways
- Affected Systems: Bing image search, Microsoft production image-processing workers, Windows servers, Linux machines
- Action Required: Microsoft has released patches for the vulnerabilities associated with CVE-2026-32194.
- Timeline: Newly disclosed
Original Article Summary
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. Microsoft issued two critical CVEs, CVE-2026-32194 and
Impact
Bing image search, Microsoft production image-processing workers, Windows servers, Linux machines
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Microsoft has released patches for the vulnerabilities associated with CVE-2026-32194. Users should ensure their systems are updated to the latest security versions and review their security configurations to prevent exploitation of this type of vulnerability.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Windows, Linux, CVE, and 4 more.