Bing 이미지 검색의 SVG 취약점으로 Microsoft 서버에서 명령어가 실행될 수 있다.
Bing 이미지 검색에 제출된 조작된 SVG가 Microsoft의 생산 이미지 처리 작업자에서 NT AUTHORITY\SYSTEM 권한으로 명령어를 실행할 수 있다는 취약점이 발견됐다. XBOW의 테스트 결과, 이 문제는 특정 머신이 아닌 Bing 이미지 계층에 존재하는 것으로 나타났다. Microsoft는 이에 대한 두 개의 심각한 CVE(CVE-2026-32194 등)를 발표했다.
Flaws in Bing's image search let crafted SVGs run commands as SYSTEM on Microsoft servers.
A vulnerability was discovered in Bing's image search where a crafted SVG could execute commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers. Testing by XBOW showed that the issue was in Bing's image tier, affecting multiple hosts rather than a single machine. Microsoft issued two critical CVEs in response, including CVE-2026-32194.