{"id":14567,"date":"2026-07-25T10:03:38","date_gmt":"2026-07-25T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/07\/25\/bing-images-vulnerability-lets-attackers-execute-remote-code-on-microsoft-servers\/"},"modified":"2026-07-25T10:03:38","modified_gmt":"2026-07-25T10:03:38","slug":"bing-images-vulnerability-lets-attackers-execute-remote-code-on-microsoft-servers","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/07\/25\/bing-images-vulnerability-lets-attackers-execute-remote-code-on-microsoft-servers\/","title":{"rendered":"Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers"},"content":{"rendered":"<p>    Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">Three critical remote code execution (RCE) vulnerabilities in Microsoft\u2019s infrastructure, with two flaws in Bing Images allowing attackers to hijack backend image-processing servers using nothing more than a crafted SVG file.<\/p>\n<p class=\"wp-block-paragraph\">The findings, disclosed responsibly by XBOW and now patched, expose how an \u201cordinary\u201d image-handling feature became a gateway to full SYSTEM-level access on production Bing servers.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft\u2019s advisories classify all three vulnerabilities as Critical, each carrying a maximum CVSS score of 9.8. <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-32194\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-32194<\/a> is a command injection flaw in Bing\u2019s image-processing pipeline, reachable through the public \u201cSearch by Image\u201d upload feature.<\/p>\n<p class=\"wp-block-paragraph\">Its sibling, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-32091\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-32191<\/a>, affects a related server-side image ingestion path tied to Bing\u2019s reverse image search crawler. A third, unrelated flaw, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-21536\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2026-21536<\/a>, involves unrestricted file upload in the Microsoft Devices Pricing Program.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiz-u5T4IhjExyesnCzhNdh5RgSKfvn59ru6xUslpDQ9UhCbmZvxKDwjq4wE3HE6gbT1s8IqrrtaZRHf6eCjESD_24Dtf24Md7G9yowpBNCHOC5I9BgMA6V9xwZt6k4UtBul9vgDch2YLVt9_YtW_ZWTOYIlJmh2ID0hM3BYnRVVwmhlSV352EwP2eInT0\/s1600\/t1%2520%281%29.webp?ssl=1\" alt=\"Bing Images visual search endpoint investigation\"><figcaption class=\"wp-element-caption\">Bing Images visual search endpoint investigation (Image Source: xbow.com)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">All three were credited to XBOW, an autonomous AI security researcher that reportedly landed in the top 10 of Microsoft\u2019s bug bounty leaderboard as the first AI to achieve that rank.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<td><strong>CVE Identifier<\/strong><\/td>\n<td><strong>Affected Component<\/strong><\/td>\n<td><strong>Root Cause Mechanism<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>CVE-2026-32194<\/strong><\/td>\n<td>Bing \u201cSearch by Image\u201d upload<\/td>\n<td>Command injection in image-processing pipeline<\/td>\n<\/tr>\n<tr>\n<td><strong>CVE-2026-32191<\/strong><\/td>\n<td>Bing reverse image search (crawler fetch)<\/td>\n<td>OS command injection in server-side image ingestion<\/td>\n<\/tr>\n<tr>\n<td><strong>CVE-2026-21536<\/strong><\/td>\n<td>Microsoft Devices Pricing Program<\/td>\n<td>Unrestricted upload of executable files<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">The investigation began almost by accident: Bing\u2019s reverse image search could be tricked into fetching an attacker-controlled URL from its backend, a classic server-side request forgery (SSRF) pattern that on its own looked low-impact.<\/p>\n<p class=\"wp-block-paragraph\">Researchers confirmed the fetch by observing outbound requests from Bing infrastructure carrying a bingbot\/2.0 user agent, then noticed inconsistent HTTP 500 errors that hinted the backend was doing more than just retrieving an image.<\/p>\n<p class=\"wp-block-paragraph\">That anomaly led investigators to test whether the fetched content was being parsed by a vulnerable component rather than simply displayed.<\/p>\n<p class=\"wp-block-paragraph\">Systematic probing ruled out XML External Entity (XXE) attacks and instead pointed to an ImageMagick-style rendering engine processing SVG files through \u201ccoders\u201d and \u201cdelegates.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Because SVG is XML-based, it can embed references to external resources or execute pseudo-protocols like label:, xc:, and pipe-based commands, features useful for trusted input but dangerous when exposed to public uploads.<\/p>\n<p class=\"wp-block-paragraph\">The successful payload inserted a pipe-prefixed shell command within an SVG reference, which led the backend\u2019s image conversion library to execute it as an operating system command instead of rendering it as an image.<\/p>\n<p class=\"wp-block-paragraph\">This SVG was submitted either directly through Bing\u2019s image upload endpoint or hosted externally and pulled in via the crawler-based SSRF path, two distinct routes into the same vulnerable delegate-backed pipeline.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjzQt5SuWIyS4ChLkqDRv0oaw6yB3IyaDThljSU1AzXT00rIaTKbA9RlxaBM77A-sxZEpbbvwaFL11PWUVGV2OLug9IGuE3xsxjdkwCpEu-jzJv71QtN22_AyPpI8VRolJN0uoCtVdhSaPtHYcaNl_mBQP0KyuF2a2viJDaFcqtbHoYBCd2jQIWkwEr2no\/s1600\/t2%2520%281%29.webp?ssl=1\" alt=\"Trace logs analyzing ImageMagick delegate vectors\"><figcaption class=\"wp-element-caption\">Trace logs analyzing ImageMagick delegate vectors (Image Source: xbow.com)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Proof of exploitation arrived via out-of-band callbacks rather than the visible HTTP response, since the frontend returned generic errors while the backend silently executed commands.<\/p>\n<p class=\"wp-block-paragraph\">Command output confirmed execution as NT AUTHORITYSYSTEM on Bing image-processing workers running Windows Server 2022 Datacenter, with results reproduced across multiple hosts and network ranges indicating the exposure spanned Bing\u2019s image-processing tier, not a single misconfigured server.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/xbow.com\/blog\/bing-images-rce-vulnerabilities\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">XBOW researchers<\/a> also caught Linux-based workers, initially missed because their automated validator only recognized Linux-style output like uid=0(user) gid=0(group), until they retooled it to also catch Windows proof commands such as whoami \/all and systeminfo.<\/p>\n<p class=\"wp-block-paragraph\">This is not a novel bug; <a href=\"https:\/\/cybersecuritynews.com\/ivanti-command-injection-vulnerability-exploit\/\" target=\"_blank\" rel=\"noreferrer noopener\">command injection<\/a> through image converters has plagued software for years, as seen in ImageTragick and similar ExifTool-based RCEs disclosed via GitLab\u2019s bug bounty program.<\/p>\n<p class=\"wp-block-paragraph\">What made this case notable was that applications treat image parsers as inert \u201cplumbing,\u201d when in reality these helpers carry decades of format compatibility and shell-out behavior that attackers can weaponize.<\/p>\n<h2 id=\"h-takeaway-for-defenders\" class=\"wp-block-heading\"><strong>Takeaway for Defenders<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Organizations running similar image-processing pipelines should take several precautions:<\/p>\n<ul class=\"wp-block-list\">\n<li>Disable shell-invoking delegates and pipe-based delegate behavior in ImageMagick-style converters.<\/li>\n<li>Enforce restrictive policy.xml and delegates.xml configurations, disallowing high-risk formats like SVG, MVG, and EPS unless explicitly required.<\/li>\n<li>Implement strict egress controls, including destination allowlists and internal-address blocking, for any feature that fetches user-supplied URLs.<\/li>\n<li>Run image conversion in sandboxed environments with reduced privileges and constrained outbound network access.<\/li>\n<li>Build validation harnesses that account for heterogeneous server fleets (Linux and Windows) to avoid missing real exploitation signals.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">Microsoft has fully remediated both Bing Images vulnerabilities in its cloud service, though the underlying lesson extends well beyond Bing: any application accepting image uploads or fetching external image URLs should treat its conversion pipeline as untrusted, security-critical code rather than harmless media handling<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><strong>\u00a0Strengthen Your SOC by Accelerating Threat Detection &amp; Rapid Investigations.\u00a0-&gt;\u00a0<a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener\">Integrate ANY.RUN With Your SOC\u00a0<\/a><strong><a href=\"https:\/\/any.run\/enterprise\/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=sandbox&amp;utm_content=enterprise&amp;utm_term=0626#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener\">Now<\/a><\/strong>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/bing-images-vulnerability\/\">Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/bing-images-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers Three critical remote code execution (RCE) vulnerabilities in Microsoft\u2019s infrastructure, with two flaws in Bing Images allowing attackers to hijack backend image-processing servers using nothing more than a crafted SVG file. The findings, disclosed responsibly by XBOW and now patched, expose how an \u201cordinary\u201d [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,131,648],"tags":[130],"class_list":["post-14567","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14567"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=14567"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14567\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=14567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=14567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=14567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}