Security · 2h ago
Bing Image Flaws Let SVGs Execute Commands as SYSTEM
Crafted SVGs submitted to Bing Images ran commands as SYSTEM on Microsoft's servers and as root on Linux machines. XBOW found the issue across multiple hosts, confirming it was in Bing's image tier. Microsoft issued two critical CVEs, CVE-2026-32194 and CVE-2026-32195.
Meridian48 take
The bugs show how even mature services like Bing can harbor deep-seated code execution flaws in image processing pipelines.
Read the full reporting
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers →
The Hacker News
microsoft-bingsvg-exploit