Skip to main content
CyberConfirmedHighDevelopingFeatured
10.0

Critical RCE vulnerability in Bing Image processing allows remote code execution as SYSTEM/root

A security researcher identified a vulnerability in Bing's image processing pipeline where a maliciously crafted SVG file triggers remote code execution (RCE) with elevated privileges on Microsoft's backend servers. The exploit requires no user interaction, posing a significant risk to infrastructure integrity. It remains unclear if this vulnerability was exploited in the wild prior to disclosure.

The Hacker Newsabout 3 hours agoUSCredibility 53%View source

Score Breakdown

Mosaic Score10.0
Confidence0.9
Significance0.8
Source credibility0.5

Intelligence Tags

Locations

Microsoft servers

Entities

country
Source

Related signals

8 found