klotz: cybersecurity linux*

0 bookmark(s) - Sort by: Date ↓ / Title / - Bookmarks from other users for this tag

  1. Security startup XBOW discovered critical flaws in Bing Image Search that allow specially crafted SVG files to execute commands with high privileges, including NT AUTHORITYSYSTEM on Windows and root on Linux. These vulnerabilities, identified as CVE-2026-32194 and CVE-2026-32191 (both rated 9.8 CVSS), exploit the way image processing workers utilize ImageMagick delegates to handle file conversion processes.

    * The flaws allow for remote code execution via both direct SVG uploads and by providing a URL of a malicious SVG fetched by Bingbot.
    * Microsoft has already implemented server-side fixes, meaning no user action is required to resolve the issue.
    * The exploit works by using an image reference within the SVG that triggers shell commands when processed through enabled delegates.
    * Experts recommend disabling ImageMagick delegates and restricting supported file formats like SVG or EPS to mitigate this class of vulnerability.

Top of the page

First / Previous / Next / Last / Page 1 of 0 SemanticScuttle - klotz.me: Tags: cybersecurity  linux

About - Propulsed by SemanticScuttle