Bing Image Processing Executes User-Supplied SVG as SYSTEM
A crafted SVG submitted to Bing Images ran commands as SYSTEM on Microsoft's production image servers. CVE-2026-32194 (CVSS 9.8) is now patched.
- Vendor
- Microsoft
- Product
- Bing Image Processing Infrastructure
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
Microsoft’s Bing image search processed user-supplied SVG files inside a worker process running as NT AUTHORITY\SYSTEM on Windows and as root on Linux. Security firm XBOW reported that a crafted SVG could execute arbitrary commands in that context across multiple hosts in Bing’s image-processing fleet — the issue was in the tier’s design, not isolated to a single machine.
Microsoft assigned multiple critical CVEs addressing the findings. CVE-2026-32194, rated CVSS 9.8 Critical, covers the primary server-side code execution path on the Windows side. Patches are deployed to Microsoft’s infrastructure. No end-user action is required. Full research detail is available in the XBOW writeup via The Hacker News.
