Microsoft: Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers

Microsoft: Bing Images Vulnerability Lets Attackers Execute Remote Code on Microsoft Servers

Critical Microsoft Bing RCE Vulnerabilities Patched After AI-Led Discovery

Three critical remote code execution (RCE) vulnerabilities in Microsoft’s infrastructure two in Bing Images and one in the Microsoft Devices Pricing Program were recently disclosed and patched. The flaws, all rated with a maximum CVSS score of 9.8, allowed attackers to gain SYSTEM-level access on production servers using crafted SVG files.

The vulnerabilities were identified by XBOW, an autonomous AI security researcher and the first AI to rank in Microsoft’s top 10 bug bounty leaderboard. The most severe flaws, CVE-2026-32194 and CVE-2026-32191, affected Bing’s image-processing pipeline, enabling command injection via the "Search by Image" upload feature and reverse image search crawler, respectively. A third flaw, CVE-2026-21536, involved unrestricted file uploads in the Microsoft Devices Pricing Program.

The attack vector exploited ImageMagick-style rendering engines, which processed SVG files containing malicious shell commands. By embedding pipe-prefixed commands within SVG references, attackers could trigger arbitrary code execution on backend servers. Exploitation was confirmed across multiple Windows Server 2022 Datacenter hosts, with some Linux-based workers also affected.

The investigation began when researchers noticed Bing’s reverse image search could be manipulated into fetching attacker-controlled URLs, leading to server-side request forgery (SSRF). Further analysis revealed that the backend parsed SVG files in a way that allowed command injection, bypassing frontend error handling to execute commands silently.

Microsoft has since patched all three vulnerabilities, but the incident underscores broader risks in image-processing pipelines, which are often treated as low-risk "plumbing" despite their potential for exploitation. Similar flaws, such as ImageTragick and ExifTool-based RCEs, have been exploited in the past, highlighting the need for stricter security controls in media-handling components.

Source: https://cybersecuritynews.com/bing-images-vulnerability/

Microsoft Security Response Center cybersecurity rating report: https://www.rankiteo.com/company/microsoft-security-response-center

"id": "MIC1784910234",
"linkid": "microsoft-security-response-center",
"type": "Vulnerability",
"date": "6/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Technology',
                        'name': 'Microsoft',
                        'type': 'Corporation'}],
 'attack_vector': 'Crafted SVG files with malicious shell commands processed '
                  'by ImageMagick-style rendering engines',
 'data_breach': {'file_types_exposed': ['SVG']},
 'description': 'Three critical remote code execution (RCE) vulnerabilities in '
                'Microsoft’s infrastructure (two in Bing Images and one in the '
                'Microsoft Devices Pricing Program) were recently disclosed '
                'and patched. The flaws, all rated with a maximum CVSS score '
                'of 9.8, allowed attackers to gain SYSTEM-level access on '
                'production servers using crafted SVG files.',
 'impact': {'operational_impact': 'Potential SYSTEM-level access on production '
                                  'servers',
            'systems_affected': ['Windows Server 2022 Datacenter',
                                 'Linux-based workers']},
 'investigation_status': 'Patched',
 'lessons_learned': 'Incident underscores broader risks in image-processing '
                    'pipelines, which are often treated as low-risk despite '
                    'their potential for exploitation. Highlights the need for '
                    'stricter security controls in media-handling components.',
 'post_incident_analysis': {'corrective_actions': 'Patches applied to '
                                                  'vulnerabilities in Bing '
                                                  'Images and Microsoft '
                                                  'Devices Pricing Program',
                            'root_causes': 'ImageMagick-style rendering '
                                           'engines processing SVG files with '
                                           'malicious shell commands, '
                                           'bypassing frontend error handling'},
 'recommendations': 'Implement stricter security controls in image-processing '
                    'and media-handling components to prevent similar '
                    'vulnerabilities.',
 'references': [{'source': 'AI security researcher XBOW'}],
 'response': {'containment_measures': 'Patches applied to vulnerabilities',
              'remediation_measures': 'Vulnerabilities patched by Microsoft'},
 'title': 'Critical Microsoft Bing RCE Vulnerabilities Patched After AI-Led '
          'Discovery',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': ['CVE-2026-32194',
                             'CVE-2026-32191',
                             'CVE-2026-21536']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.