HackerFeeds

CyberSecurity News

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

The Hacker News
· July 24, 2026

AI summary

Vulnerabilities in Bing Images allowed specially crafted SVG files to execute commands with high privileges on Microsoft's servers. These commands could run as NT AUTHORITY\SYSTEM on Windows machines and as root on Linux machines within the same fleet. The issue was not isolated to a single machine, but rather was a problem with Bing's image processing tier. Microsoft addressed the vulnerabilities by issuing two critical CVEs. The flaws could be exploited by submitting a crafted SVG to Bing's image search. The vulnerabilities were identified by XBOW during testing across different hosts and network ranges.

Read the full article at The Hacker Newsthehackernews.com/2026/07/bing-images-flaws-let-crafted-svgs-run.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.