As cited
Copy frozen at (site build).
vulnerabilities
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
A researcher demonstrated that maliciously crafted SVG files submitted to Bing's image search could execute arbitrary commands with SYSTEM privileges on Microsoft's production image-processing infrastructure, affecting both Windows and Linux servers. Microsoft addressed the issue by issuing two critical CVEs for the vulnerability in Bing's image processing tier.
Why it matters: Organizations relying on Bing's image search or similar image processing services should verify patch status; the SYSTEM-level execution risk exposes backend infrastructure and potentially data accessible to those services.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
A researcher demonstrated that maliciously crafted SVG files submitted to Bing's image search could execute arbitrary commands with SYSTEM privileges on Microsoft's production image-processing infrastructure, affecting both Windows and Linux servers. Microsoft addressed the issue by issuing two critical CVEs for the vulnerability in Bing's image processing tier.
Why it matters: Organizations relying on Bing's image search or similar image processing services should verify patch status; the SYSTEM-level execution risk exposes backend infrastructure and potentially data accessible to those services.
- Source published
- First seen by Cybersecurity Tracker