[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fK-dO89BP9HE2tKBFQH1-2e1ljvBmmRjDWSC2wXZlWjo":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"93a5c3a6-e25c-4bd4-b29a-4951aed02670","malicious-svgs-enabled-system-level-rce-on-bing-image-servers","13016a28-8c7c-4327-a8ea-1892a0a172ce","Malicious SVGs Enabled SYSTEM-Level RCE on Bing Image Servers","Attackers could craft malicious SVG files to exploit ImageMagick's delegate functionality and shell command injection vulnerabilities, achieving full SYSTEM-level code execution on Microsoft's Bing image-processing infrastructure. The root issue lies in trusting user-supplied file content without sufficient sanitization before passing it to a powerful, feature-rich third-party processing library. ImageMagick's delegate system, which invokes shell commands to handle certain file formats, has a well-documented history of dangerous misuse — yet it remained insufficiently hardened in this production environment. This matters because server-side image processing pipelines are a common but underestimated attack surface, and SYSTEM\u002Froot-level compromise means complete loss of server confidentiality, integrity, and availability.","**Immediate actions:**\n- Audit all image-processing pipelines for use of ImageMagick and disable or restrict dangerous delegate configurations (e.g., via a hardened `policy.xml`).\n- Apply vendor patches for CVE-2026-32194 and CVE-2026-32191 immediately and verify patched versions are running in all environments.\n\n**Long-term improvements:**\n- Run image-processing workers in isolated, least-privilege containers or sandboxes so that exploitation cannot yield SYSTEM\u002Froot on the host.\n- Replace or wrap feature-rich libraries like ImageMagick with purpose-built, minimal-attack-surface alternatives where full functionality is not required.\n- Maintain a software composition inventory (SBOM) to rapidly identify all services consuming vulnerable third-party libraries when new CVEs are disclosed.\n\n**Detection measures:**\n- Monitor image-processing worker processes for anomalous child process spawning or unexpected outbound network connections indicative of command injection.\n- Implement file-type validation and content inspection (magic bytes, schema enforcement) on all user-uploaded files before they reach processing workers.\n- Establish automated vulnerability scanning of server-side dependencies on a scheduled cadence to catch known-vulnerable library versions before exploitation occurs.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 16: Application Software Security","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 SI-10: Information Input Validation","NIST SP 800-53 AC-6: Least Privilege","NIST SP 800-53 SC-39: Process Isolation","NIST SP 800-218 (SSDF) PW.6: Use Vetted Software with Secure Configurations","OWASP ASVS V12: File and Resource Upload Verification","OWASP Top 10 A03:2021 – Injection","published","2026-07-24T14:22:31.925776+00:00","2026-07-24T14:22:31.601+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fbing-images-flaws-let-crafted-svgs-run.html","bing-images-flaws-let-crafted-svgs-run-commands-as-system-on-microsoft-s-servers-3f283a","Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]