top of page
perceptive_background_267k.jpg

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

Published:

22 april 2026 om 22:00:00

Alert date:

23 april 2026 om 23:04:51

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Critical Infrastructure

A critical deserialization vulnerability in Microsoft Bing allows unauthorized attackers to execute arbitrary code remotely over a network. The vulnerability stems from improper handling of untrusted data during deserialization processes. This represents a significant security risk as it enables remote code execution without authentication. The vulnerability affects Microsoft's Bing search service infrastructure. Given the widespread use of Bing services, this vulnerability could have broad impact if exploited.

Technical details

Mitigation steps:

Affected products:

Microsoft Bing

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page