Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

A critical vulnerability has been discovered in Bing Images, allowing attackers to execute arbitrary commands with elevated privileges on Microsoft’s servers by uploading crafted SVG images. This flaw affects anyone who uses Bing Images to upload pictures, making it a significant concern for users of the popular search engine.

The bug lies in the way Bing handles uploaded SVG files. When an attacker uploads a specially crafted SVG image, the server fails to properly validate and sanitize the file’s contents. This allows the malicious code within the SVG to be executed with SYSTEM privileges, giving the attacker complete control over the affected server. The vulnerability can also be exploited remotely, making it a potential target for hackers.

Microsoft servers are not the only ones at risk; any system that uses Bing Images or its underlying infrastructure is vulnerable to this attack. This includes Windows desktops and laptops, as well as other devices running Microsoft software. While the primary concern is for users of Bing Images, the broader impact on Microsoft’s ecosystem makes this a critical issue.

The vulnerability was discovered by security researchers using artificial intelligence-powered tools. These models can rapidly scan codebases and identify potential weaknesses that human developers may miss. However, the same AI-driven approach that helped find this flaw also highlights the challenges of securing software today. With more code being written every day, the pressure on developers to keep up with vulnerabilities is mounting.

Microsoft has not yet commented on the specifics of the patch or how long it will take to fix the issue. Given the severity of this vulnerability, users are advised to exercise caution when uploading files to Bing Images and consider using alternative search engines that may be less susceptible to these types of attacks. Additionally, organizations should review their security protocols to ensure they can detect and respond quickly to similar threats in the future.

To protect yourself from vulnerabilities like this one, it’s essential to stay up-to-date with software patches and regularly scan your systems for potential weaknesses. By taking proactive steps to secure your devices and applications, you can reduce the risk of falling victim to sophisticated attacks like this one.


Source: The Hacker News — 2026-07-24