SVG image with script payload in onload handler
A reported Bing Images issue shows how dangerous vector graphics can be: crafted SVG files were found able to execute commands as SYSTEM on Microsoft's servers. SVG is a text-based markup format, so it can carry JavaScript inside element handlers, and rendering an innocuous-looking image can silently run that script in the application's security context. Attackers weaponize this to drop payloads, steal cookies, or pivot within a session. In this demo a benign SVG runs only a harmless onload alert to illustrate the mechanism. Deep CDR parses and rebuilds the SVG, stripping script and ActiveX-style content while preserving the visual output. A sanitized image reaches the endpoint — no executable script ever runs.
Attack Technique
SVG embedded script
MITRE ATT&CK
T1059.007 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗