Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers 23%

By Swati Khandelwal11%

7/24/2026, 11:45:00 AM

BS Summary: This article contains 22 faulty reasoning types, including Negativity Bias, Appeal to Authority, and Overconfidence Bias, with Indoctrination as the most egregious example at 15.8% saturation with 141 hits. Analysis detected 910 faulty-reasoning hits from 893 analyzed words, generating a BS Score of 36.2% and a BS Rank of 23% (16,928 of 21,887 articles). This article is better (less manipulative) than 77.30% of the article peer group.

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. 
XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine. 
Microsoft issued two critical CVEs, CVE-2026-32194 and CVE-2026-32191, and rated both 9.8 on the CVSS scale. 
XBOW, the autonomous offensive security startup, found both and reported them privately. 
Bing users have no patch or mitigation to apply: Microsoft fixed both server-side before the advisories went out in March, and the records state there is "no customer action to resolve." 
Neither advisory recorded exploitation or public disclosure when they went up on March 19. 
XBOW published the exploit mechanics on July 23, after holding them back at Microsoft's request until the remediation had landed. 
What outlives the fix is the shape of the bug. 
The application believed it was handling an image; the helper underneath read part of that image as a command. 
If your own stack pipes uploads or server-fetched URLs through ImageMagick or anything ImageMagick-compatible, your exposure turns on whether attacker-controlled content can still reach a delegate-enabled path. 
Deny the delegates, cut the formats you accept, and keep the worker off the network, and the same SVG does nothing. 
Bing's reverse image search fetches an image URL from the backend, because that is what the feature does. 
On its own, that is a blind SSRF: nothing comes back to the client. 
The tell was the error. 
Some workers returned a 500 to the browser and still fetched and parsed what they retrieved, which pointed at something downstream doing the parsing. 
SVG answered that question. 
It is XML, not pixels: it can reference other images, and a renderer that follows those references goes and gets them. 
Underneath, conversion suites hand formats they do not process themselves to a delegate, an external program invoked through a shell. 
On the path XBOW reached, that layer was still enabled, so an image reference beginning with a pipe character went to the shell rather than being read as a filename. 
The payload was a one-pixel SVG whose reference ran a command on the worker and curled the output back to a collector XBOW controlled. 
That gave two routes into the same conversion tier and two CVEs. 
CVE-2026-32194, filed as command injection under CWE-77, is the public "Search by Image" upload, with the SVG going in base64 as the imageBin field to /images/kblob. 
CVE-2026-32191, filed as OS command injection under CWE-78, is the crawler route: host the SVG anywhere, hand its URL to the search through the imgurl parameter, and bingbot/2.0 fetches it into the same pipeline. 
Neither needs authentication, cookies, session state or a click. 
The Hacker News checked both CVE records on July 24. 
Both still carry Microsoft's March status of no public disclosure, which XBOW's writeup has overtaken, and Microsoft still lists them as not exploited. 
The proof had to come out of band. 
The frontend could return an error while the worker executed anyway. 
Linux workers returned uid=0 and gid=0. 
On Windows, systeminfo named Windows Server 2022 Datacenter, whoami /all showed SeImpersonatePrivilege and SeDebugPrivilege enabled, and directory listings put execution inside Bing's multimedia image-processing components. 
The firm says it ran only benign read-only commands and touched no customer data. 
Narrowing it to that path took dozens of probes. 
ImageMagick pseudo-protocols came back differently depending on the coder: label: rendered text and xc: produced a color image, while text:, caption: and direct file reads failed. 
Shell metacharacters inside label: rendered as text rather than executing, which ruled that coder out. 
The path that did reach a delegate was the image reference inside the SVG itself. 
Turn the delegates off 
An image-processing worker handling untrusted files should not reach a shell, run as SYSTEM, or have a way out to the internet. 
Bing's pipeline did all three. 
ImageMagick's own guidance is explicit that the default policy is open and meant for sandboxed or firewalled use, not a public website. 
For anything touching untrusted images, deny delegates outright in policy.xml: 
<policy domain="delegate" rights="none" pattern="*" /> 
Then, in order of what buys you most: 
Cut the formats you accept. 
SVG, MVG and EPS are among those that carry references and interpreters. 
Review delegates.xml and disable anything enabled that you do not need. 
Run conversion sandboxed and with reduced privileges. 
Block outbound network from the worker, which is the leg that turned a blind bug into a proven one. 
Allowlist the destinations a server-side fetch may reach, and keep the worker off internal addresses. 
ImageMagick's guidance is to test after any policy change, and magick identify -list policy prints what is actually loaded. 
ImageTragick, the 2016 delegate command injection tracked as CVE-2016-3714, is the same class of failure, and it keeps resurfacing because nobody counts the converter as part of the attack surface. 
XBOW CISO Nico Waisman, who wrote the disclosure, put it this way: "Applications treat image helpers as plumbing. 
Attackers treat them as parsers." 
The fetch was reachable, returned nothing, and looked like a dead end. 
What turned it into a SYSTEM shell was the parser behind it, and nothing in the response would have told you so. 
Article reasoning-pattern comparisonThis article: 2.6%Swati Khandelwal: 2.4%The Hacker News: 1.9%Confirmation Bias2.6%This article: 5.6%Swati Khandelwal: 1.5%The Hacker News: 1.2%Anchoring Bias5.6%This article: 4.8%Swati Khandelwal: 3.5%The Hacker News: 3.3%Availability Heuristic4.8%This article: 0.0%Swati Khandelwal: 1.4%The Hacker News: 1.5%Representativeness Heuristic0.0%This article: 4.8%Swati Khandelwal: 0.7%The Hacker News: 0.6%Hindsight Bias4.8%This article: 6.4%Swati Khandelwal: 2.4%The Hacker News: 2.5%Overconfidence Bias6.4%This article: 1.6%Swati Khandelwal: 2.8%The Hacker News: 2.7%Framing Effect1.6%This article: 0.0%Swati Khandelwal: 0.9%The Hacker News: 1.0%Loss Aversion0.0%This article: 5.9%Swati Khandelwal: 0.7%The Hacker News: 0.6%Status Quo Bias5.9%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 3.2%Swati Khandelwal: 1.2%The Hacker News: 1.3%Optimism Bias3.2%This article: 0.0%Swati Khandelwal: 1.9%The Hacker News: 1.6%Pessimism Bias0.0%This article: 14.6%Swati Khandelwal: 6.3%The Hacker News: 6.7%Negativity Bias14.6%This article: 1.6%Swati Khandelwal: 0.4%The Hacker News: 0.8%Self-Serving Bias1.6%This article: 2.5%Swati Khandelwal: 0.4%The Hacker News: 0.4%Fundamental Attribution Error2.5%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 4.5%Swati Khandelwal: 1.5%The Hacker News: 1.5%Recency Bias4.5%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 8.3%Swati Khandelwal: 3.9%The Hacker News: 4.0%Appeal to Authority8.3%This article: 0.9%Swati Khandelwal: 1.3%The Hacker News: 1.6%False Dilemma0.9%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 4.4%Swati Khandelwal: 3.8%The Hacker News: 4.3%Hasty Generalization4.4%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.2%Bandwagon0.0%This article: 0.0%Swati Khandelwal: 0.8%The Hacker News: 1.1%Appeal to Emotion0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.5%Begging the Question0.0%This article: 5.5%Swati Khandelwal: 2.0%The Hacker News: 1.9%Post Hoc (False Cause)5.5%This article: 1.6%Swati Khandelwal: 0.0%The Hacker News: 0.0%Tu Quoque1.6%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 1.3%Swati Khandelwal: 0.3%The Hacker News: 0.3%Composition/Division1.3%This article: 0.0%Swati Khandelwal: 1.1%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 1.6%Swati Khandelwal: 2.5%The Hacker News: 2.3%Ambiguity (Equivocation)1.6%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 2.6%Swati Khandelwal: 1.0%The Hacker News: 1.4%Unattributed Quote2.6%This article: 2.0%Swati Khandelwal: 0.8%The Hacker News: 0.9%Quote-first Misdirection2.0%This article: 0.0%Swati Khandelwal: 2.7%The Hacker News: 2.3%Biased Writer Voice0.0%This article: 15.8%Swati Khandelwal: 5.0%The Hacker News: 4.4%Indoctrination15.8%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

893 words analyzed.

Speakers

3speakers6.4%attributed speech836writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 13 words • 0.0% coverageWriter's voice • 29 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageXBOW • 12 words • 0.0% coverageWriter's voice • 31 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 27 words • 100.0% coverageWriter's voice • 21 words • 100.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 34 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 4 words • 100.0% coverageWriter's voice • 22 words • 100.0% coverageWriter's voice • 5 words • 0.0% coverageImageMagick's own guidance • 22 words • 0.0% coverageWriter's voice • 10 words • 100.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 5 words • 100.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 11 words • 100.0% coverageWriter's voice • 7 words • 100.0% coverageWriter's voice • 19 words • 100.0% coverageWriter's voice • 15 words • 100.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 30 words • 0.0% coverageNico Waisman • 18 words • 100.0% coverageNico Waisman • 5 words • 100.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 22 words • 0.0% coverage
Selected voice

Nico Waisman

100%flagged-word coverage
23 attributed words40% of attributed speech64% writer coverage
0%50.0%100.0%Unattributed Quote+100.0 ptsWriter: 0.0%Nico Waisman: 100.0%100.0%Quote-first Misdirection+78.3 ptsWriter: 0.0%Nico Waisman: 78.3%78.3%Indoctrination-16.9 ptsWriter: 16.9%Nico Waisman: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.