AI description
CVE-2026-32191 is an OS command injection vulnerability found in Microsoft Bing Images. This flaw allows an unauthorized attacker to execute arbitrary code over a network. The vulnerability stems from the improper neutralization of special elements used in OS commands, specifically CWE-78, which enables attackers to inject malicious commands into system shells. This occurs when user-controlled input is passed unsanitized to system command execution functions within Microsoft Bing Images. The vulnerability was discovered by XBOW's autonomous offensive security system, which identified that a crafted SVG submitted to Bing's image search could run commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers. Microsoft has since released a security update and fully mitigated this vulnerability for cloud service users, with no customer action required.
- Description
- Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- CNA Tags
- exclusively-hosted-service
- Products
- bing_images
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- secure@microsoft.com
- CWE-78
- Hype score
- Not currently trending
XBOW, an autonomous AI pentesting agent, found two critical flaws in Bing image-processing servers: a crafted SVG ran commands as SYSTEM and as root. CVE-2026-32194 and CVE-2026-32191, both CVSS 9.8. Microsoft patched server-side before disclosure on July 23. #AIsecurity #CVE
@SEatTrend
27 Jul 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
1/3 A single crafted SVG uploaded to Bing image search ran commands as SYSTEM on Microsoft's own servers. Two OS command injection bugs (CVE-2026-32194, CVE-2026-32191) let an image reach a shell with full privileges. Microsoft has patched. #CyberSecurity #InfoSec #CVE https://t.
@CyberTLDR
25 Jul 2026
398 Impressions
0 Retweets
2 Likes
3 Bookmarks
1 Reply
0 Quotes
⚠️ ALERTA DE VULNERABILIDAD 📅 24/07/2026 💥 Impacto: Ejecución de código 🔴 Severidad: Crítica 🎯 CVEs: CVE-2026-32194, CVE-2026-32191, CVE-2026-21536 Afecta a productos de Microsoft (Bing e imágenes). ¡Aplica parches oficiales! #Cybersecurity #TechNews #CVE
@BetoDay
25 Jul 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Two critical RCE flaws (CVSS 9.8), CVE-2026-32194 & CVE-2026-32191, in Bing Images let attackers hijack backend servers using just a crafted SVG file — achieving SYSTEM-level access via command injection in the image-processing pipeline. Discovered by AI security rese
@techepages
24 Jul 2026
1130 Impressions
0 Retweets
4 Likes
1 Bookmark
0 Replies
0 Quotes
Critical vulnerabilities in Bing Images, identified as CVE-2026-32194 and CVE-2026-32191, allow remote code execution via crafted SVG files. These flaws, now patched, underscore the importance of robust input validation in image-processing pipelines to prevent command injection h
@dailytechonx
24 Jul 2026
192 Impressions
0 Retweets
2 Likes
3 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:bing_images:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5B3D4053-7DAF-4AB9-86E8-33D45C8EF86B",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]