Cybersecurity · 28 views
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet.
AI Summary
A vulnerability in Bing's image processing system has been discovered, allowing crafted SVGs to run commands with elevated privileges on Microsoft's servers. This flaw, which was identified by security researchers at XBOW, enables attackers to submit malicious SVGs to Bing's image search, which are then processed by Microsoft's servers. The crafted images can execute commands with the highest level of access, including SYSTEM on Windows machines and root on Linux machines. The issue appears to be specific to Bing's image tier, as testing across different hosts and network ranges yielded the same result. Microsoft has issued a response, but the details of their actions are not specified in the report.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedMore from Cybersecurity
Continue reading recent Cybersecurity coverage
- This Key Will Self-Destruct: An Open Standard for Revocable API KeysContinue reading
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside SandboxContinue reading
- Man gets 15 years for extorting women with AI-generated porn videosContinue reading
- New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM accessContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow