內容說明

微軟釋出115年4月份安全性更新,共修補165個漏洞,其中包含8個高風險漏洞與1個已遭利用之漏洞,請儘速確認並進行修補。 本篇整理重點為 CVE-2026-0390、CVE-2026-20806、CVE-2026-20928、CVE-2026-20930、CVE-2026-20945等 165 項 CVE。校內若有使用相關平台,應依影響版本盤點並安排修補。


影響平台

  • 【具高風險漏洞之產品】
  • Azure Logic Apps
  • Microsoft Power Apps
  • Remote Desktop Client
  • SQL Server
  • Windows Advanced Rasterization Platform
  • Windows IKE Extension
  • Windows Push Notifications
  • Windows Shell
  • 【其他受影響產品】
  • .NET
  • .NET Framework
  • .NET and Visual Studio
  • .NET, .NET Framework, Visual Studio
  • Applocker Filter Driver (applockerfltr.sys)
  • Azure Monitor Agent
  • Desktop Window Manager
  • Function Discovery Service (fdwsd.dll)
  • GitHub Copilot and Visual Studio Code
  • Microsoft Brokering File System
  • Microsoft Defender
  • Microsoft Dynamics 365 (on-premises)
  • Microsoft Edge (Chromium-based)
  • Microsoft Graphics Component
  • Microsoft High Performance Compute Pack (HPC)
  • Microsoft Management Console
  • Microsoft Office
  • Microsoft Office Excel
  • Microsoft Office PowerPoint
  • Microsoft Office SharePoint
  • Microsoft Office Word
  • Microsoft PowerShell
  • Microsoft Windows
  • Microsoft Windows Search Component
  • Microsoft Windows Speech
  • Role: Windows Hyper-V
  • Universal Plug and Play (upnp.dll)
  • Windows Active Directory
  • Windows Admin Center
  • Windows Ancillary Function Driver for WinSock
  • Windows Biometric Service
  • Windows BitLocker
  • Windows Boot Loader
  • Windows Boot Manager
  • Windows COM
  • Windows Client Side Caching driver (csc.sys)
  • Windows Cloud Files Mini Filter Driver
  • Windows Common Log File System Driver
  • Windows Container Isolation FS Filter Driver
  • Windows Cryptographic Services
  • Windows Encrypting File System (EFS)
  • Windows File Explorer
  • Windows GDI
  • Windows HTTP.sys
  • Windows Hello
  • Windows Installer
  • Windows Kerberos
  • Windows Kernel
  • Windows Kernel Memory
  • Windows LUAFV
  • Windows Local Security Authority Subsystem Service (LSASS)
  • Windows Management Services
  • Windows OLE
  • Windows Print Spooler Components
  • Windows Projected File System
  • Windows RPC API
  • Windows Recovery Environment Agent
  • Windows Redirected Drive Buffering
  • Windows Remote Desktop
  • Windows Remote Desktop Licensing Service
  • Windows Remote Procedure Call
  • Windows SSDP Service
  • Windows Sensor Data Service
  • Windows Server Update Service
  • Windows Snipping Tool
  • Windows Speech Brokered Api
  • Windows Storage Spaces Controller
  • Windows TCP/IP
  • Windows TDI Translation Driver (tdx.sys)
  • Windows USB Print Driver
  • Windows Universal Plug and Play (UPnP) Device Host
  • Windows User Interface Core
  • Windows Virtualization-Based Security (VBS) Enclave
  • Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys)
  • Windows WalletService
  • Windows Win32K - GRFX
  • Windows Win32K - ICOMP

處置建議

  • 目前微軟官方已針對弱點釋出修復版本,請各機關可聯絡系統維護廠商或參考以下連結:
  • https://msrc.microsoft.com/update-guide/releaseNote/2026-Apr
  • CVE編號
  • 【高風險漏洞】
  • CVE-2026-26149
  • CVE-2026-26167
  • CVE-2026-26178
  • CVE-2026-32157
  • CVE-2026-32171
  • CVE-2026-32225
  • CVE-2026-33120
  • CVE-2026-33824
  • 【其他漏洞】
  • CVE-2026-0390
  • CVE-2026-20806
  • CVE-2026-20928
  • CVE-2026-20930
  • CVE-2026-20945
  • CVE-2026-23653
  • CVE-2026-23657
  • CVE-2026-23666
  • CVE-2026-23670
  • CVE-2026-25184
  • CVE-2026-26143
  • CVE-2026-26151
  • CVE-2026-26152
  • CVE-2026-26153
  • CVE-2026-26154
  • CVE-2026-26155
  • CVE-2026-26156
  • CVE-2026-26159
  • CVE-2026-26160
  • CVE-2026-26161
  • CVE-2026-26162
  • CVE-2026-26163
  • CVE-2026-26165
  • CVE-2026-26166
  • CVE-2026-26168
  • CVE-2026-26169
  • CVE-2026-26170
  • CVE-2026-26171
  • CVE-2026-26172
  • CVE-2026-26173
  • CVE-2026-26174
  • CVE-2026-26175
  • CVE-2026-26176
  • CVE-2026-26177
  • CVE-2026-26179
  • CVE-2026-26180
  • CVE-2026-26181
  • CVE-2026-26182
  • CVE-2026-26183
  • CVE-2026-26184
  • CVE-2026-27906
  • CVE-2026-27907
  • CVE-2026-27908
  • CVE-2026-27909
  • CVE-2026-27910
  • CVE-2026-27911
  • CVE-2026-27912
  • CVE-2026-27913
  • CVE-2026-27914
  • CVE-2026-27915
  • CVE-2026-27916
  • CVE-2026-27917
  • CVE-2026-27918
  • CVE-2026-27919
  • CVE-2026-27920
  • CVE-2026-27921
  • CVE-2026-27922
  • CVE-2026-27923
  • CVE-2026-27924
  • CVE-2026-27925
  • CVE-2026-27926
  • CVE-2026-27927
  • CVE-2026-27928
  • CVE-2026-27929
  • CVE-2026-27930
  • CVE-2026-27931
  • CVE-2026-32068
  • CVE-2026-32069
  • CVE-2026-32070
  • CVE-2026-32071
  • CVE-2026-32072
  • CVE-2026-32073
  • CVE-2026-32074
  • CVE-2026-32075
  • CVE-2026-32076
  • CVE-2026-32077
  • CVE-2026-32078
  • CVE-2026-32079
  • CVE-2026-32080
  • CVE-2026-32081
  • CVE-2026-32082
  • CVE-2026-32083
  • CVE-2026-32084
  • CVE-2026-32085
  • CVE-2026-32086
  • CVE-2026-32087
  • CVE-2026-32088
  • CVE-2026-32089
  • CVE-2026-32090
  • CVE-2026-32091
  • CVE-2026-32093
  • CVE-2026-32149
  • CVE-2026-32150
  • CVE-2026-32151
  • CVE-2026-32152
  • CVE-2026-32153
  • CVE-2026-32154
  • CVE-2026-32155
  • CVE-2026-32156
  • CVE-2026-32158
  • CVE-2026-32159
  • CVE-2026-32160
  • CVE-2026-32162
  • CVE-2026-32163
  • CVE-2026-32164
  • CVE-2026-32165
  • CVE-2026-32167
  • CVE-2026-32168
  • CVE-2026-32176
  • CVE-2026-32178
  • CVE-2026-32181
  • CVE-2026-32183
  • CVE-2026-32184
  • CVE-2026-32188
  • CVE-2026-32189
  • CVE-2026-32190
  • CVE-2026-32192
  • CVE-2026-32195
  • CVE-2026-32196
  • CVE-2026-32197
  • CVE-2026-32198
  • CVE-2026-32199
  • CVE-2026-32200
  • CVE-2026-32201
  • CVE-2026-32202
  • CVE-2026-32203
  • CVE-2026-32212
  • CVE-2026-32214
  • CVE-2026-32215
  • CVE-2026-32216
  • CVE-2026-32217
  • CVE-2026-32218
  • CVE-2026-32219
  • CVE-2026-32220
  • CVE-2026-32221
  • CVE-2026-32222
  • CVE-2026-32223
  • CVE-2026-32224
  • CVE-2026-32226
  • CVE-2026-33095
  • CVE-2026-33096
  • CVE-2026-33098
  • CVE-2026-33099
  • CVE-2026-33100
  • CVE-2026-33101
  • CVE-2026-33103
  • CVE-2026-33104
  • CVE-2026-33114
  • CVE-2026-33115
  • CVE-2026-33116
  • CVE-2026-33118
  • CVE-2026-33119
  • CVE-2026-33822
  • CVE-2026-33825
  • CVE-2026-33826
  • CVE-2026-33827
  • CVE-2026-33829
  • 盤點校內是否使用受影響版本,包含自管、委外代管與專案環境。
  • 依官方或廠商公告套用修補版本;若短期無法更新,先限制管理介面來源並強化監控。
  • 檢查近期管理帳號登入、設定異動、異常腳本或未知管理操作紀錄。

CVE編號

  • CVE-2026-0390
  • CVE-2026-20806
  • CVE-2026-20928
  • CVE-2026-20930
  • CVE-2026-20945
  • CVE-2026-23653
  • CVE-2026-23657
  • CVE-2026-23666
  • CVE-2026-23670
  • CVE-2026-25184
  • CVE-2026-26143
  • CVE-2026-26149
  • CVE-2026-26151
  • CVE-2026-26152
  • CVE-2026-26153
  • CVE-2026-26154
  • CVE-2026-26155
  • CVE-2026-26156
  • CVE-2026-26159
  • CVE-2026-26160
  • CVE-2026-26161
  • CVE-2026-26162
  • CVE-2026-26163
  • CVE-2026-26165
  • CVE-2026-26166
  • CVE-2026-26167
  • CVE-2026-26168
  • CVE-2026-26169
  • CVE-2026-26170
  • CVE-2026-26171
  • CVE-2026-26172
  • CVE-2026-26173
  • CVE-2026-26174
  • CVE-2026-26175
  • CVE-2026-26176
  • CVE-2026-26177
  • CVE-2026-26178
  • CVE-2026-26179
  • CVE-2026-26180
  • CVE-2026-26181
  • CVE-2026-26182
  • CVE-2026-26183
  • CVE-2026-26184
  • CVE-2026-27906
  • CVE-2026-27907
  • CVE-2026-27908
  • CVE-2026-27909
  • CVE-2026-27910
  • CVE-2026-27911
  • CVE-2026-27912
  • CVE-2026-27913
  • CVE-2026-27914
  • CVE-2026-27915
  • CVE-2026-27916
  • CVE-2026-27917
  • CVE-2026-27918
  • CVE-2026-27919
  • CVE-2026-27920
  • CVE-2026-27921
  • CVE-2026-27922
  • CVE-2026-27923
  • CVE-2026-27924
  • CVE-2026-27925
  • CVE-2026-27926
  • CVE-2026-27927
  • CVE-2026-27928
  • CVE-2026-27929
  • CVE-2026-27930
  • CVE-2026-27931
  • CVE-2026-32068
  • CVE-2026-32069
  • CVE-2026-32070
  • CVE-2026-32071
  • CVE-2026-32072
  • CVE-2026-32073
  • CVE-2026-32074
  • CVE-2026-32075
  • CVE-2026-32076
  • CVE-2026-32077
  • CVE-2026-32078
  • CVE-2026-32079
  • CVE-2026-32080
  • CVE-2026-32081
  • CVE-2026-32082
  • CVE-2026-32083
  • CVE-2026-32084
  • CVE-2026-32085
  • CVE-2026-32086
  • CVE-2026-32087
  • CVE-2026-32088
  • CVE-2026-32089
  • CVE-2026-32090
  • CVE-2026-32091
  • CVE-2026-32093
  • CVE-2026-32149
  • CVE-2026-32150
  • CVE-2026-32151
  • CVE-2026-32152
  • CVE-2026-32153
  • CVE-2026-32154
  • CVE-2026-32155
  • CVE-2026-32156
  • CVE-2026-32157
  • CVE-2026-32158
  • CVE-2026-32159
  • CVE-2026-32160
  • CVE-2026-32162
  • CVE-2026-32163
  • CVE-2026-32164
  • CVE-2026-32165
  • CVE-2026-32167
  • CVE-2026-32168
  • CVE-2026-32171
  • CVE-2026-32176
  • CVE-2026-32178
  • CVE-2026-32181
  • CVE-2026-32183
  • CVE-2026-32184
  • CVE-2026-32188
  • CVE-2026-32189
  • CVE-2026-32190
  • CVE-2026-32192
  • CVE-2026-32195
  • CVE-2026-32196
  • CVE-2026-32197
  • CVE-2026-32198
  • CVE-2026-32199
  • CVE-2026-32200
  • CVE-2026-32201
  • CVE-2026-32202
  • CVE-2026-32203
  • CVE-2026-32212
  • CVE-2026-32214
  • CVE-2026-32215
  • CVE-2026-32216
  • CVE-2026-32217
  • CVE-2026-32218
  • CVE-2026-32219
  • CVE-2026-32220
  • CVE-2026-32221
  • CVE-2026-32222
  • CVE-2026-32223
  • CVE-2026-32224
  • CVE-2026-32225
  • CVE-2026-32226
  • CVE-2026-33095
  • CVE-2026-33096
  • CVE-2026-33098
  • CVE-2026-33099
  • CVE-2026-33100
  • CVE-2026-33101
  • CVE-2026-33103
  • CVE-2026-33104
  • CVE-2026-33114
  • CVE-2026-33115
  • CVE-2026-33116
  • CVE-2026-33118
  • CVE-2026-33119
  • CVE-2026-33120
  • CVE-2026-33822
  • CVE-2026-33824
  • CVE-2026-33825
  • CVE-2026-33826
  • CVE-2026-33827
  • CVE-2026-33829

參考資料