Critical Bing Image Flaw Allows SVGs to Execute Commands as SYSTEM

A crafted SVG submitted to Bing image search can execute commands as NT AUTHORITY\SYSTEM on Microsoft’s production servers, impacting multiple hosts with critical security implications.

Why it matters

The vulnerability enables remote code execution with SYSTEM-level privileges on Microsoft cloud infrastructure, increasing the risk of unauthorized control over critical services.

SOC impact

Analyze logs for unusual SVG file submissions to Bing image search and monitor server telemetry for unexpected command execution events with elevated privileges. Review impacted hosts for indicators of exploitation related to the two disclosed CVEs targeting the image processing tier.

Recommended actions

  1. Review Bing image search logs for suspicious SVG uploads
  2. Monitor for command execution events linked to image processing services
  3. Inventory affected Microsoft production hosts
  4. Assess exposure to the two critical CVEs issued by Microsoft
  5. Correlate telemetry for unusual activity in image processing components

Executive Summary

A critical vulnerability in Bing’s image search processing allows specially crafted SVG files to execute system-level commands on Microsoft’s production servers. This flaw affects multiple hosts and has been addressed by two critical CVEs targeting the image handling components. Given the SYSTEM-level access granted to attackers, the vulnerability poses a significant risk to Microsoft’s cloud infrastructure security. Security teams should prioritize identifying signs of exploitation and reviewing relevant telemetry to detect any unauthorized command execution attempts related to this flaw.

SOC Impact

Analyze logs for unusual SVG file submissions to Bing image search and monitor server telemetry for unexpected command execution events with elevated privileges. Review impacted hosts for indicators of exploitation related to the two disclosed CVEs targeting the image processing tier.

Detection and Exposure Assessment

  • Review Bing image search logs for suspicious SVG uploads
  • Monitor for command execution events linked to image processing services
  • Inventory affected Microsoft production hosts
  • Assess exposure to the two critical CVEs issued by Microsoft
  • Correlate telemetry for unusual activity in image processing components

Why It Matters

The vulnerability enables remote code execution with SYSTEM-level privileges on Microsoft cloud infrastructure, increasing the risk of unauthorized control over critical services.

Source