Microsoft ปล่อยอัปเดตนอกกำหนดเมื่อ 20 พฤษภาคม 2026 เพื่อแก้สองช่องโหว่ Zero‑Day ใน Microsoft Defender คือ CVE‑2026‑41091 (ยกระดับสิทธิ์) และ CVE‑2026‑45498 (ทำให้บริการล่ม) ซึ่งถูกโจมตีจริงแล้ว
ช่องโหว่ CVE‑2026‑41091 เกิดจากการจัดการลิงก์ไฟล์ผิดพลาด ทำให้ผู้ใช้ที่มีสิทธิ์ต่ำสามารถยกระดับเป็น SYSTEM และควบคุมเครื่องได้เต็มรูปแบบ
ผู้ดูแลระบบควรอัปเดต Microsoft Defender platform และ Malware Protection Engine ทันที และตรวจสอบเวอร์ชัน เนื่องจากอัปเดต Defender แยกจาก Windows Update
What are the newly disclosed Microsoft Defender zero‑day vulnerabilities patched in the May 20 out‑of‑band update (including CVE‑2026‑41091Microsoft patched two actively exploited Defender vulnerabilities in an out‑of‑band update on May 20, 2026.
AI พรอมต์
Create a landscape editorial hero image for this Studio Global article: What are the newly disclosed Microsoft Defender zero‑day vulnerabilities patched in the May 20 out‑of‑band update (including CVE‑2026‑41091. Article summary: Microsoft’s May 20, 2026 out-of-band Defender update addressed two newly disclosed, actively exploited Defender flaws: CVE-2026-41091, a local privilege-escalation link-following bug, and CVE-2026-45498, a Defender denia. Topic tags: general, government, general web, user generated, education. Reference image context from search candidates: Reference image 1: visual subject ""The May 2026 Patch Tuesday Release breaks a long-standing streak as the first release in nearly two years not to include a zero-day," said Satnam Narang, senior staff research eng" source context "No Zero-Days, but Plenty to Patch in Microsoft May Update" Reference image 2: visual subject "
openai.com
Microsoft ได้ออก อัปเดตความปลอดภัยแบบเร่งด่วน (out‑of‑band) เมื่อวันที่ 20 พฤษภาคม 2026 เพื่อแก้ไขช่องโหว่สองรายการใน Microsoft Defender ที่ถูกนำไปใช้โจมตีจริงแล้ว ได้แก่ CVE‑2026‑41091 และ CVE‑2026‑45498. ช่องโหว่ทั้งสองถูกเพิ่มเข้าในรายการ Known Exploited Vulnerabilities (KEV) ของหน่วยงาน CISA ของสหรัฐฯ ซึ่งหมายความว่ามีหลักฐานการโจมตีจริงเกิดขึ้นแล้วในโลกไซเบอร์.
แม้ลักษณะทางเทคนิคของช่องโหว่จะแตกต่างกัน—หนึ่งเกี่ยวข้องกับการยกระดับสิทธิ์ และอีกหนึ่งทำให้บริการล่ม—แต่ทั้งคู่กระทบกับ Microsoft Defender ซึ่งเป็นระบบป้องกันมัลแวร์หลักของ Windows จำนวนมากทั้งในองค์กรและผู้ใช้ทั่วไป.
ช่องโหว่เหล่านี้กระทบกับ ส่วนประกอบของ Microsoft Defender ไม่ได้ขึ้นกับเวอร์ชัน Windows โดยตรง ดังนั้นเครื่องที่ใช้ Defender ใน Windows หลายเวอร์ชันจึงอาจได้รับผลกระทบ เช่น
Windows 11
Windows Server ที่เปิดใช้ Microsoft Defender
เครื่องในองค์กรที่ใช้ Microsoft Malware Protection Engine
ตรวจสอบเหตุการณ์ผิดปกติของ Defender เช่น service crash หรือ restart บ่อย
เฝ้าระวังไฟล์ symbolic link หรือ reparse point ที่ผิดปกติในโฟลเดอร์ที่ผู้ใช้เขียนได้
หากยังไม่สามารถอัปเดตได้ทันที ควรลดความเสี่ยงโดย:
จำกัดการเข้าถึงเครื่องแบบ interactive
ลดสิทธิ์ผู้ใช้ที่ไม่จำเป็น
ตรวจสอบสถานะระบบป้องกัน endpoint อย่างใกล้ชิด
ทำไมช่องโหว่ใน Defender ถึงสำคัญ
ซอฟต์แวร์ป้องกันภัยไซเบอร์อย่าง Microsoft Defender มักทำงานด้วยสิทธิ์สูงและเชื่อมโยงลึกกับระบบปฏิบัติการ Windows ดังนั้น หากตัวเครื่องมือป้องกันเองมีช่องโหว่ ก็อาจกลายเป็นจุดโจมตีที่ทรงพลังสำหรับผู้ไม่หวังดี.