Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Bing Image Bug Exploited SVGs to Execute Commands

Bing Image Bug Exploited SVGs to Execute Commands

Posted on July 24, 2026 By CWS

Security researchers have uncovered a critical vulnerability in Bing’s image processing system, where specially crafted SVG files could execute commands with elevated privileges. These SVG files, when submitted to Bing’s image search, were able to run commands as NT AUTHORITYSYSTEM on Microsoft’s servers and as root on associated Linux machines.

Discovery and Impact

The flaw was identified by XBOW, a startup specializing in offensive security. Their tests indicated that the issue was widespread across various hosts and network ranges, implicating Bing’s image processing tier rather than individual machines. Microsoft addressed the issue by releasing two critical Common Vulnerabilities and Exposures (CVEs), CVE-2026-32194 and CVE-2026-32191, both scoring 9.8 on the Common Vulnerability Scoring System (CVSS) scale.

These vulnerabilities were reported privately by XBOW, and Microsoft resolved them server-side before making any public advisories in March. It was confirmed that no customer intervention was required, as the necessary fixes had already been implemented.

Technical Breakdown of the Flaw

The flaw originated from the system’s misinterpretation of an image as a command. SVG files, which are XML-based, can reference other images. If a renderer follows these references, it could inadvertently execute commands. This vulnerability was particularly severe in systems utilizing ImageMagick or similar software, where attacker-controlled content could reach a delegate-enabled path.

The problem was exacerbated by Bing’s reverse image search functionality, which fetched image URLs from the backend. This setup resulted in a blind Server-Side Request Forgery (SSRF) with the potential for downstream parsing errors that could execute commands.

Preventative Measures and Recommendations

To mitigate such vulnerabilities, it is crucial to deny delegates in policy settings and limit the accepted file formats, especially those that can include references, like SVG. Additionally, reviewing and disabling unnecessary enabled delegates in configuration files and running conversions in a sandboxed environment with limited privileges are recommended practices.

Further, outbound network access from the worker should be restricted, preventing any server-side fetches from reaching unauthorized destinations. This approach transforms a blind bug into a managed one, reducing the risk of exploitation.

Future Outlook

ImageMagick’s past vulnerabilities, such as the 2016 ImageTragick incident, highlight the persistent risk of command injection attacks in image processing systems. Continuous vigilance and strict policy adherence are essential to safeguard against similar threats.

As XBOW’s CISO Nico Waisman noted, image helpers are often overlooked as part of the attack surface. However, attackers view them as potential parsers, capable of executing unintended actions. This incident emphasizes the need for robust security measures in handling untrusted content.

The Hacker News Tags:Bing, command execution, CVE, Cybersecurity, delegate-enabled path, image processing, ImageMagick, Microsoft, Remediation, security flaw, server-side, SVG, Vulnerabilities, XBOW, XML

Post navigation

Previous Post: JetBrains Resolves Critical IntelliJ and TeamCity Flaws
Next Post: AI Malware, Cyber Attacks & Linux Vulnerabilities Overview

Related Posts

Botnet Uses Polygon Blockchain for Resilient Command Control Botnet Uses Polygon Blockchain for Resilient Command Control The Hacker News
Critical SmartConsole Vulnerability Patched by Check Point Critical SmartConsole Vulnerability Patched by Check Point The Hacker News
Microsoft Secures Defender Against Critical Privilege Flaw Microsoft Secures Defender Against Critical Privilege Flaw The Hacker News
Developer Workstations Integral to Software Supply Chain Security Developer Workstations Integral to Software Supply Chain Security The Hacker News
Think Your IdP or CASB Covers Shadow IT? These 5 Risks Prove Otherwise Think Your IdP or CASB Covers Shadow IT? These 5 Risks Prove Otherwise The Hacker News
Microsoft Exposes AutoJack Exploit in AI Browsing Agents Microsoft Exposes AutoJack Exploit in AI Browsing Agents The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ChonkyChicken Malware Targets Chrome Credentials
  • Certighost Vulnerability Allows Domain Controller Impersonation
  • Malicious Bing Ads Exploit AI Interests to Spread Malware
  • AI Malware, Cyber Attacks & Linux Vulnerabilities Overview
  • Bing Image Bug Exploited SVGs to Execute Commands

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ChonkyChicken Malware Targets Chrome Credentials
  • Certighost Vulnerability Allows Domain Controller Impersonation
  • Malicious Bing Ads Exploit AI Interests to Spread Malware
  • AI Malware, Cyber Attacks & Linux Vulnerabilities Overview
  • Bing Image Bug Exploited SVGs to Execute Commands

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark