Three critical remote code execution (RCE) vulnerabilities in Microsoft’s infrastructure, with two flaws in Bing Images allowing attackers to hijack backend image-processing servers using nothing more than a crafted SVG file. The findings, disclosed responsibly by XBOW and now patched, expose how an “ordinary” image-handling feature became a gateway to full SYSTEM-level access on production Bing servers. Microsoft’s advisories classify all three vulnerabilities as Critical, each carrying a maximum CVSS score of 9.8. CVE-2026-32194 is a command injection flaw in Bing’s image-processing pipeline, reachable through the public “Search by Image” upload feature. Its sibling, CVE-2026-32191,...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!