SVG Image Vulnerabilities on Microsoft's Image Processing Servers

A recent vulnerability in Microsoft's image processing infrastructure has been discovered, allowing malicious actors to run commands on servers running Windows operating systems, and Linux machines. The vulnerability was discovered by XBOW, a security firm, who reported the issue to Microsoft.

According to XBOW, a malicious actor could craft an SVG image file with malicious code that, when submitted to Bing's image search, would execute the commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers. This privilege escalation allowed the attacker to access sensitive data and potentially disrupt the server's operations.

Further testing revealed that the issue was not isolated to a single host or network range, but rather affected workers across different hosts and network ranges, indicating that the problem was inherent in the system. XBOW's testing also showed that the vulnerability was reproducible on Linux machines, where the attacker could run commands as root.

The vulnerability was identified through a combination of manual testing and automated tools, and XBOW reported the issue to Microsoft in a responsible disclosure manner. Microsoft subsequently acknowledged the issue and released a patch to address the vulnerability.

Source: The Hacker News