跳到主要內容區

2026-09-10 【漏洞預警】 Microsoft Windows存在兩項高風險漏洞(CVE-2026-81963、CVE-2026-85880)遭利用,請評估進行修補作業。

轉發金融資安資訊分享與分析中心

內容說明:
Microsoft Windows存在兩項權限提升漏洞,說明如下:
1. CVE-2026-81963:Windows Update Stack存在檔案存取前連結解析不當(Improper Link Resolution Before File Access)漏洞,已獲授權的攻擊者可利用該漏洞於本機提升權限。
2. CVE-2026-85880:Windows Advanced Local Procedure Call(ALPC)存在堆積型緩衝區溢位(Heap-based Buffer Overflow)漏洞,已獲授權的攻擊者可利用該漏洞於本機提升權限。

已揭露攻擊活動說明:
1. Microsoft已確認兩項漏洞均已遭利用。
2. CISA已納入漏洞利用清單。

 
影響平台:
1. CVE-2026-81963(Windows Update Stack):
(1) Windows 11 Version 23H2受影響,建議更新至Build 10.0.22631.7582或以上版本。
(2) Windows 11 Version 24H2受影響,建議更新至Build 10.0.26100.9445或以上版本。
(3) Windows 11 Version 25H2受影響,建議更新至Build 10.0.26200.9445或以上版本。
(4) Windows 11 Version 26H1受影響,建議更新至Build 10.0.28000.2954或以上版本。
(5) Windows Server 2025(含Server Core installation)受影響,建議更新至Build 10.0.26100.33438或以上版本。
2. CVE-2026-85880(Windows Advanced Local Procedure Call,ALPC):
(1) Windows Server 2012(含Server Core installation)受影響,建議更新至Build 6.2.9200.26349或以上版本。
(2) Windows Server 2012 R2(含Server Core installation)受影響,建議更新至Build 6.3.9600.23397或以上版本。
(3) Windows Server 2016(含Server Core installation)及Windows 10 Version 1607受影響,建議更新至Build 10.0.14393.9512或以上版本。
(4) Windows Server 2019(含Server Core installation)及Windows 10 Version 1809受影響,建議更新至Build 10.0.17763.9245或以上版本。
(5) Windows 10 Version 21H2受影響,建議更新至Build 10.0.19044.7725或以上版本。
(6) Windows 10 Version 22H2受影響,建議更新至Build 10.0.19045.7725或以上版本。
(7) Windows Server 2022(含Server Core installation)受影響,建議更新至Build 10.0.20348.5622或以上版本。

 

解決辦法:
1. 官方已發布修補程式,建議依據單位內漏洞管理機制進行相關作業。
 

瀏覽數: