{"id":424231,"date":"2026-07-29T08:40:00","date_gmt":"2026-07-29T08:40:00","guid":{"rendered":"https:\/\/dailybanglanewspapers.com\/news\/critical-bing-images-flaws-let-attackers-run-code-on-microsoft-servers\/"},"modified":"2026-07-29T08:40:00","modified_gmt":"2026-07-29T08:40:00","slug":"critical-bing-images-flaws-let-attackers-run-code-on-microsoft-servers","status":"publish","type":"post","link":"https:\/\/dailybanglanewspapers.com\/news\/critical-bing-images-flaws-let-attackers-run-code-on-microsoft-servers\/","title":{"rendered":"Critical Bing Images Flaws Let Attackers Run Code on Microsoft Servers"},"content":{"rendered":"<p><\/p>\n<div>\n<p><a data-autolink-id=\"235\" target=\"_self\" href=\"https:\/\/inews.zoombangla.com\/category\/english\/business-english\/technology\/\">Microsoft<\/a>\u2018s Bing Images faced not one but two critical remote code execution flaws that allowed hackers to run system-level commands on backend servers. The vulnerabilities\u2014CVE-2026-32194 and CVE-2026-32191\u2014both scored a maximum CVSS of 9.8, requiring no authentication or user privileges to exploit.<\/p>\n<p><img fetchpriority=\"high\" data-perfmatters-preload=\"\" fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/inews.zoombangla.com\/wp-content\/uploads\/2026\/07\/Bing-Images-RCE-vulnerability-CVE.jpg\" alt=\"Bing Images RCE vulnerability CVE\" width=\"900\" height=\"470\" class=\"alignnone size-full wp-image-3267562\" srcset=\"https:\/\/inews.zoombangla.com\/wp-content\/uploads\/2026\/07\/Bing-Images-RCE-vulnerability-CVE.jpg 900w, https:\/\/inews.zoombangla.com\/wp-content\/uploads\/2026\/07\/Bing-Images-RCE-vulnerability-CVE.jpg 1200w\" sizes=\"(max-width: 767px) 100vw, 900px\"\/><\/p>\n<p>The attack worked by uploading a specially crafted SVG image through Bing\u2019s public \u201cSearch by Image\u201d feature. The image processing pipeline then handed the file to ImageMagick, an open-source image library with a dangerous default: it automatically delegates certain file types to helper programs, including Ghostscript for PostScript files. A malicious SVG could trick ImageMagick into executing arbitrary shell commands, running as NT AUTHORITY\\SYSTEM on Windows Server 2022 Datacenter.<\/p>\n<h2>How the Attack Worked<\/h2>\n<p>An attacker didn\u2019t need a Bing account, API key, or session token. They could upload a poisoned image directly through the web interface. The vulnerability lived in two paths: the public-facing \u201cSearch by Image\u201d upload (CVE-2026-32194) and Bing\u2019s reverse-image-search crawler route (CVE-2026-32191). Both led to the same backend image processing workers, both exploitable via SVG polyglots\u2014files that are valid SVGs but contain embedded PostScript that triggers code execution.<\/p>\n<p>Researchers at XBOW security lab discovered the flaw and notified Microsoft. The company had already patched the issue on its servers back in March 2026, months before the public disclosure. But for three months after the fix, attackers could have used this to hijack Bing\u2019s image-processing infrastructure.<\/p>\n<h2>What This Reveals<\/h2>\n<p>ImageMagick\u2019s delegate feature is a well-known footgun in the security world. The library is installed on millions of servers worldwide, often configured to \u201cjust work\u201d out of the box\u2014meaning delegate programs are enabled by default. Any application that processes user-uploaded images and passes them to ImageMagick without sandboxing is potentially vulnerable to the same attack class.<\/p>\n<p>This is not an ImageMagick problem alone. It\u2019s a cascade problem: permissive defaults in image libraries, combined with deployment practices that don\u2019t restrict what commands those libraries can invoke, combined with insufficient input validation. Microsoft\u2019s responsibility was to harden the image pipeline. The company did. But thousands of other services running similar setups may not have.<\/p>\n<h2>Lessons for Defenders<\/h2>\n<p>If your application processes images uploaded by users, assume the file is hostile. Use a sandboxed image processor. Restrict ImageMagick\u2019s delegates. Disable formats you don\u2019t need. Or use a library with secure defaults\u2014something designed to be attacked and hardened, not something designed to be flexible and later secured.<\/p>\n<p>Microsoft fixed this three months ago. But the disclosure matters. Researchers can now test their own systems using the same technique.<\/p>\n<h4>FYI (keeping you in the loop)<\/h4>\n<details>\n<summary>Did attackers use this vulnerability?<\/summary>\n<p>Microsoft has not disclosed evidence of active exploitation. The flaw was fixed before public disclosure. But a three-month window is long enough for Nation states and sophisticated threat actors to have discovered and weaponized it independently.<\/p>\n<\/details>\n<h4>References<\/h4>\n<p>The Hacker News. (2026). Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft\u2019s Servers. Published July 2026.<\/p>\n<p>CyberSecurityNews. (2026). Bing Images Vulnerability Let Attackers Execute Remote Code on Microsoft Servers Using SVG File. Published July 2026.<\/p>\n<p>SentinelOne. (2026). CVE-2026-32191: Microsoft Bing Images RCE Vulnerability. Published July 2026.<\/p>\n<div class=\"code-block code-block-center code-block-4\">\n<div style=\"max-width:760px;margin:18px auto;padding:16px 18px;background:#f8f9fa;border:1px solid #dadce0;border-radius:16px;font-family:Arial,sans-serif;box-sizing:border-box;\">\n<div style=\"display:flex;align-items:center;justify-content:space-between;gap:14px;\">\n<div style=\"display:flex;align-items:center;gap:12px;min-width:0;\"><img width=\"696\" height=\"696\" decoding=\"async\" alt=\"Zoom Bangla News\" style=\"width:48px;height:48px;border-radius:50%;object-fit:cover;display:block;flex-shrink:0;\" class=\"perfmatters-lazy\" src=\"https:\/\/inews.zoombangla.com\/wp-content\/uploads\/2026\/05\/zoombangla_org_logo_696-yoast.png\"\/><\/p>\n<div style=\"min-width:0;\">\n<p>\nZoom Bangla News<\/p>\n<p>\ninews.zoombangla.com<\/p>\n<\/div>\n<\/div>\n<p><a href=\"https:\/\/www.google.com\/preferences\/source?cs=0&amp;hl=en&amp;q=inews.zoombangla.com\" target=\"_blank\" rel=\"noopener noreferrer\" style=\"background:#1a73e8;color:#fff;text-decoration:none;font-size:14px;font-weight:600;padding:10px 18px;border-radius:10px;display:inline-flex;align-items:center;justify-content:center;white-space:nowrap;flex-shrink:0;\"><br \/>\nFollow<br \/>\n<\/a><\/div>\n<div style=\"margin-top:14px;padding-top:14px;border-top:1px solid #e5e7eb;text-align:center;\">\n<p style=\"margin:0 0 8px;font-size:16px;font-weight:700;color:#111827;line-height:1.35;\">\nFollow iNews Zoombangla On Google<\/p>\n<p style=\"margin:0 auto 12px;font-size:13px;line-height:1.6;color:#4b5563;max-width:620px;\">\nOpen the Google follow page and tap the checkmark option to receive more updates from iNews Zoombangla in your Google news feed.<\/p>\n<p><a href=\"https:\/\/www.google.com\/preferences\/source?cs=0&amp;hl=en&amp;q=inews.zoombangla.com\" target=\"_blank\" rel=\"noopener noreferrer\" style=\"display:block;text-decoration:none;max-width:640px;margin:0 auto;\" aria-label=\"Follow iNews Zoombangla On Google\"><br \/>\n<img decoding=\"async\" height=\"123\" width=\"653\" alt=\"Follow iNews Zoombangla On Google\" style=\"width:100%;height:auto;border-radius:12px;border:1px solid #dfe1e5;display:block;\" class=\"perfmatters-lazy\" src=\"https:\/\/inews.zoombangla.com\/wp-content\/uploads\/2026\/05\/1-17.jpg\"\/><br \/>\n<\/a><\/div>\n<\/div>\n<\/div>\n<p><input id=\"daextamp-post-id\" type=\"hidden\" value=\"3267527\"\/><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft\u2018s Bing Images faced not one but two critical remote code execution flaws that allowed hackers to run system-level commands on backend servers. The vulnerabilities\u2014CVE-2026-32194 and CVE-2026-32191\u2014both scored a maximum CVSS of 9.8, requiring no authentication or user privileges to exploit. The attack worked by uploading a specially crafted SVG image through Bing\u2019s public \u201cSearch [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":424232,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"fifu_image_url":"https:\/\/inews.zoombangla.com\/wp-content\/uploads\/2026\/07\/Bing-Images-RCE-vulnerability-CVE.jpg","fifu_image_alt":"","footnotes":""},"categories":[10],"tags":[],"class_list":["post-424231","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-lifestyle"],"acf":[],"_links":{"self":[{"href":"https:\/\/dailybanglanewspapers.com\/news\/wp-json\/wp\/v2\/posts\/424231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dailybanglanewspapers.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dailybanglanewspapers.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dailybanglanewspapers.com\/news\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/dailybanglanewspapers.com\/news\/wp-json\/wp\/v2\/comments?post=424231"}],"version-history":[{"count":0,"href":"https:\/\/dailybanglanewspapers.com\/news\/wp-json\/wp\/v2\/posts\/424231\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dailybanglanewspapers.com\/news\/wp-json\/wp\/v2\/media\/424232"}],"wp:attachment":[{"href":"https:\/\/dailybanglanewspapers.com\/news\/wp-json\/wp\/v2\/media?parent=424231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dailybanglanewspapers.com\/news\/wp-json\/wp\/v2\/categories?post=424231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dailybanglanewspapers.com\/news\/wp-json\/wp\/v2\/tags?post=424231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}