Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
Summary
Researchers discovered vulnerabilities in Bing's image processing that allowed specially crafted SVG files to execute arbitrary commands on Microsoft's servers, including as SYSTEM on Windows and root on Linux. Microsoft has addressed these flaws by issuing two critical CVEs.
IFF Assessment
This discovery represents a significant security flaw that could be exploited to gain unauthorized access and execute code on critical infrastructure.
Severity
The vulnerability allows for remote code execution with high privileges (SYSTEM/root) on Microsoft's servers, impacting integrity, confidentiality, and availability. The attack vector is likely network-based and requires minimal user interaction (uploading an SVG), making it highly exploitable.
Defender Context
This incident highlights the ongoing risk of complex supply chain and third-party vulnerabilities, even within large tech companies. Defenders should prioritize rapid patching and robust input validation for all user-submitted content, especially in services that process rich media.