內容說明

微軟釋出115年3月份安全性更新,共修補包含SQL Server、Microsoft Office SharePoint及Active Directory Domain Services等共84個漏洞,其中包含16個CVSS達8.8分之高風險漏洞,請儘速確認並進行修補。 本篇整理重點為 CVE-2026-20967、CVE-2026-21262、CVE-2026-21536、CVE-2026-23651、CVE-2026-23654等 84 項 CVE。校內若有使用相關平台,應依影響版本盤點並安排修補。


影響平台

  • .NET
  • ASP.NET Core
  • Active Directory Domain Services
  • Azure Arc
  • Azure Compute Gallery
  • Azure Entra ID
  • Azure IoT Explorer
  • Azure Linux Virtual Machines
  • Azure MCP Server
  • Azure Portal Windows Admin Center
  • Azure Windows Virtual Machine Agent
  • Broadcast DVR
  • Connected Devices Platform Service(Cdpsvc)
  • GitHub Repo: zero-shot-scfoundation
  • Microsoft Authenticator
  • Microsoft Brokering File System
  • Microsoft Devices Pricing Program
  • Microsoft Graphics Component
  • Microsoft Office
  • Microsoft Office Excel
  • Microsoft Office SharePoint
  • Microsoft Semantic Kernel Python SDK
  • Payment Orchestrator Service
  • Push Message Routing Service
  • Role: Windows Hyper-V
  • SQL Server
  • System Center Operations Manager
  • Windows Accessibility Infrastructure(ATBroker.exe)
  • Windows Ancillary Function Driver for WinSock
  • Windows App Installer
  • Windows Authentication Methods
  • Windows Bluetooth RFCOM Protocol Driver
  • Windows DWM Core Library
  • Windows Device Association Service
  • Windows Extensible File Allocation
  • Windows File Server
  • Windows GDI
  • Windows GDI+
  • Windows Kerberos
  • Windows Kernel
  • Windows MapUrlToZone
  • Windows Mobile Broadband
  • Windows NTFS
  • Windows Performance Counters
  • Windows Print Spooler Components
  • Windows Projected File System
  • Windows Resilient File System(ReFS)
  • Windows Routing and Remote Access Service(RRAS)
  • Windows SMB Server
  • Windows Shell Link Processing
  • Windows System Image Manager
  • Windows Telephony Service
  • Windows Universal Disk Format File System Driver(UDFS)
  • Windows Win32K
  • Winlogon

處置建議

  • 目前微軟官方已針對弱點釋出修復版本,請各機關可聯絡系統維護廠商或參考以下連結:
  • https://msrc.microsoft.com/update-guide/releaseNote/2026-Mar
  • CVE編號
  • CVE-2026-20967
  • CVE-2026-21262
  • CVE-2026-21536
  • CVE-2026-23651
  • CVE-2026-23654
  • CVE-2026-23656
  • CVE-2026-23660
  • CVE-2026-23661
  • CVE-2026-23662
  • CVE-2026-23664
  • CVE-2026-23665
  • CVE-2026-23667
  • CVE-2026-23668
  • CVE-2026-23669
  • CVE-2026-23671
  • CVE-2026-23672
  • CVE-2026-23673
  • CVE-2026-23674
  • CVE-2026-24282
  • CVE-2026-24283
  • CVE-2026-24285
  • CVE-2026-24287
  • CVE-2026-24288
  • CVE-2026-24289
  • CVE-2026-24290
  • CVE-2026-24291
  • CVE-2026-24292
  • CVE-2026-24293
  • CVE-2026-24294
  • CVE-2026-24295
  • CVE-2026-24296
  • CVE-2026-24297
  • CVE-2026-25165
  • CVE-2026-25166
  • CVE-2026-25167
  • CVE-2026-25168
  • CVE-2026-25169
  • CVE-2026-25170
  • CVE-2026-25171
  • CVE-2026-25172
  • CVE-2026-25173
  • CVE-2026-25174
  • CVE-2026-25175
  • CVE-2026-25176
  • CVE-2026-25177
  • CVE-2026-25178
  • CVE-2026-25179
  • CVE-2026-25180
  • CVE-2026-25181
  • CVE-2026-25185
  • CVE-2026-25186
  • CVE-2026-25187
  • CVE-2026-25188
  • CVE-2026-25189
  • CVE-2026-25190
  • CVE-2026-26030
  • CVE-2026-26105
  • CVE-2026-26106
  • CVE-2026-26107
  • CVE-2026-26108
  • CVE-2026-26109
  • CVE-2026-26110
  • CVE-2026-26111
  • CVE-2026-26112
  • CVE-2026-26113
  • CVE-2026-26114
  • CVE-2026-26115
  • CVE-2026-26116
  • CVE-2026-26117
  • CVE-2026-26118
  • CVE-2026-26121
  • CVE-2026-26122
  • CVE-2026-26123
  • CVE-2026-26124
  • CVE-2026-26125
  • CVE-2026-26127
  • CVE-2026-26128
  • CVE-2026-26130
  • CVE-2026-26131
  • CVE-2026-26132
  • CVE-2026-26134
  • CVE-2026-26141
  • CVE-2026-26144
  • CVE-2026-26148
  • 盤點校內是否使用受影響版本,包含自管、委外代管與專案環境。
  • 依官方或廠商公告套用修補版本;若短期無法更新,先限制管理介面來源並強化監控。
  • 檢查近期管理帳號登入、設定異動、異常腳本或未知管理操作紀錄。

CVE編號

  • CVE-2026-20967
  • CVE-2026-21262
  • CVE-2026-21536
  • CVE-2026-23651
  • CVE-2026-23654
  • CVE-2026-23656
  • CVE-2026-23660
  • CVE-2026-23661
  • CVE-2026-23662
  • CVE-2026-23664
  • CVE-2026-23665
  • CVE-2026-23667
  • CVE-2026-23668
  • CVE-2026-23669
  • CVE-2026-23671
  • CVE-2026-23672
  • CVE-2026-23673
  • CVE-2026-23674
  • CVE-2026-24282
  • CVE-2026-24283
  • CVE-2026-24285
  • CVE-2026-24287
  • CVE-2026-24288
  • CVE-2026-24289
  • CVE-2026-24290
  • CVE-2026-24291
  • CVE-2026-24292
  • CVE-2026-24293
  • CVE-2026-24294
  • CVE-2026-24295
  • CVE-2026-24296
  • CVE-2026-24297
  • CVE-2026-25165
  • CVE-2026-25166
  • CVE-2026-25167
  • CVE-2026-25168
  • CVE-2026-25169
  • CVE-2026-25170
  • CVE-2026-25171
  • CVE-2026-25172
  • CVE-2026-25173
  • CVE-2026-25174
  • CVE-2026-25175
  • CVE-2026-25176
  • CVE-2026-25177
  • CVE-2026-25178
  • CVE-2026-25179
  • CVE-2026-25180
  • CVE-2026-25181
  • CVE-2026-25185
  • CVE-2026-25186
  • CVE-2026-25187
  • CVE-2026-25188
  • CVE-2026-25189
  • CVE-2026-25190
  • CVE-2026-26030
  • CVE-2026-26105
  • CVE-2026-26106
  • CVE-2026-26107
  • CVE-2026-26108
  • CVE-2026-26109
  • CVE-2026-26110
  • CVE-2026-26111
  • CVE-2026-26112
  • CVE-2026-26113
  • CVE-2026-26114
  • CVE-2026-26115
  • CVE-2026-26116
  • CVE-2026-26117
  • CVE-2026-26118
  • CVE-2026-26121
  • CVE-2026-26122
  • CVE-2026-26123
  • CVE-2026-26124
  • CVE-2026-26125
  • CVE-2026-26127
  • CVE-2026-26128
  • CVE-2026-26130
  • CVE-2026-26131
  • CVE-2026-26132
  • CVE-2026-26134
  • CVE-2026-26141
  • CVE-2026-26144
  • CVE-2026-26148

參考資料