Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Bing Image Bug Exploited SVGs to Execute Commands

Bing Image Bug Exploited SVGs to Execute Commands

Posted on July 24, 2026 By CWS

Security researchers have uncovered a critical vulnerability in Bing’s image processing system, where specially crafted SVG files could execute commands with elevated privileges. These SVG files, when submitted to Bing’s image search, were able to run commands as NT AUTHORITYSYSTEM on Microsoft’s servers and as root on associated Linux machines.

Discovery and Impact

The flaw was identified by XBOW, a startup specializing in offensive security. Their tests indicated that the issue was widespread across various hosts and network ranges, implicating Bing’s image processing tier rather than individual machines. Microsoft addressed the issue by releasing two critical Common Vulnerabilities and Exposures (CVEs), CVE-2026-32194 and CVE-2026-32191, both scoring 9.8 on the Common Vulnerability Scoring System (CVSS) scale.

These vulnerabilities were reported privately by XBOW, and Microsoft resolved them server-side before making any public advisories in March. It was confirmed that no customer intervention was required, as the necessary fixes had already been implemented.

Technical Breakdown of the Flaw

The flaw originated from the system’s misinterpretation of an image as a command. SVG files, which are XML-based, can reference other images. If a renderer follows these references, it could inadvertently execute commands. This vulnerability was particularly severe in systems utilizing ImageMagick or similar software, where attacker-controlled content could reach a delegate-enabled path.

The problem was exacerbated by Bing’s reverse image search functionality, which fetched image URLs from the backend. This setup resulted in a blind Server-Side Request Forgery (SSRF) with the potential for downstream parsing errors that could execute commands.

Preventative Measures and Recommendations

To mitigate such vulnerabilities, it is crucial to deny delegates in policy settings and limit the accepted file formats, especially those that can include references, like SVG. Additionally, reviewing and disabling unnecessary enabled delegates in configuration files and running conversions in a sandboxed environment with limited privileges are recommended practices.

Further, outbound network access from the worker should be restricted, preventing any server-side fetches from reaching unauthorized destinations. This approach transforms a blind bug into a managed one, reducing the risk of exploitation.

Future Outlook

ImageMagick’s past vulnerabilities, such as the 2016 ImageTragick incident, highlight the persistent risk of command injection attacks in image processing systems. Continuous vigilance and strict policy adherence are essential to safeguard against similar threats.

As XBOW’s CISO Nico Waisman noted, image helpers are often overlooked as part of the attack surface. However, attackers view them as potential parsers, capable of executing unintended actions. This incident emphasizes the need for robust security measures in handling untrusted content.

The Hacker News Tags:Bing, command execution, CVE, Cybersecurity, delegate-enabled path, image processing, ImageMagick, Microsoft, Remediation, security flaw, server-side, SVG, Vulnerabilities, XBOW, XML

Post navigation

Previous Post: JetBrains Resolves Critical IntelliJ and TeamCity Flaws
Next Post: AI Malware, Cyber Attacks & Linux Vulnerabilities Overview

Related Posts

How To Automate Ticket Creation, Device Identification and Threat Triage With Tines How To Automate Ticket Creation, Device Identification and Threat Triage With Tines The Hacker News
New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts The Hacker News
NASA’s AIT-GUI Vulnerabilities Pose Severe Security Risks NASA’s AIT-GUI Vulnerabilities Pose Severe Security Risks The Hacker News
Australian Duo Charged in Global Cybercrime Operation Australian Duo Charged in Global Cybercrime Operation The Hacker News
Revolutionizing SOC: AI-Powered Hypothesis Investigation Revolutionizing SOC: AI-Powered Hypothesis Investigation The Hacker News
New TETRA Radio Encryption Flaws Expose Law Enforcement Communications New TETRA Radio Encryption Flaws Expose Law Enforcement Communications The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Phasing Out Manifest V2 Extensions by 2027
  • Sensitive Employee Data Breach at Natural Resources Wales
  • Hackers Exploit Google Services for Phishing Scams
  • Stealth Linux Rootkit Targets F5 BIG-IP Servers
  • PEEP Exploits Chrome and Edge for Host Command Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Phasing Out Manifest V2 Extensions by 2027
  • Sensitive Employee Data Breach at Natural Resources Wales
  • Hackers Exploit Google Services for Phishing Scams
  • Stealth Linux Rootkit Targets F5 BIG-IP Servers
  • PEEP Exploits Chrome and Edge for Host Command Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark