Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

Summary

Researchers discovered vulnerabilities in Bing's image processing that allowed specially crafted SVG files to execute arbitrary commands on Microsoft's servers, including as SYSTEM on Windows and root on Linux. Microsoft has addressed these flaws by issuing two critical CVEs.

IFF Assessment

FOE

This discovery represents a significant security flaw that could be exploited to gain unauthorized access and execute code on critical infrastructure.

Severity

9.8 Critical

The vulnerability allows for remote code execution with high privileges (SYSTEM/root) on Microsoft's servers, impacting integrity, confidentiality, and availability. The attack vector is likely network-based and requires minimal user interaction (uploading an SVG), making it highly exploitable.

Defender Context

This incident highlights the ongoing risk of complex supply chain and third-party vulnerabilities, even within large tech companies. Defenders should prioritize rapid patching and robust input validation for all user-submitted content, especially in services that process rich media.

Read Full Story →