CISA 在 2026 年 5 月將兩個 Microsoft Defender 零日漏洞加入 KEV 目錄:CVE‑2026‑41091(權限提升)同 CVE‑2026‑45498(拒絕服務)。 CVE‑2026‑41091 屬於高危漏洞,CVSS 3.1 評分 7.8,源於 Defender 在存取檔案前錯誤解析連結(link following)。

Create a landscape editorial hero image for this Studio Global article: What are the details of the two actively exploited Microsoft Defender zero‑day vulnerabilities (CVE‑2026‑41091 and CVE‑2026‑45498) that CISA. Article summary: Microsoft Defender had two actively exploited zero-days added to CISA’s KEV catalog in May 2026: CVE-2026-41091, a local privilege-escalation flaw, and CVE-2026-45498, a denial-of-service flaw. The available evidence con. Topic tags: general, government, general web, user generated. Reference image context from search candidates: Reference image 1: visual subject "# CISA Confirms Active Exploitation of Six Microsoft Zero-Days: What You Need to Know About Patch Tuesday. HackYourMom / News / CISA Confirms Active Exploitation of Six Microsoft Z" source context "CISA Confirms Active Exploitation of Six Microsoft Zero-Days: What You Need to Know About Patch Tuesday
2026 年 5 月,美國網絡安全與基礎設施安全局(CISA)將兩個 Microsoft Defender 漏洞加入 Known Exploited Vulnerabilities(KEV)目錄,代表安全機構已確認這些漏洞正在現實攻擊中被利用。兩個漏洞分別是 CVE‑2026‑41091 同 CVE‑2026‑45498。
KEV 目錄係 CISA 用嚟提醒政府機構同企業優先修補高風險漏洞嘅官方清單。一旦漏洞被列入,聯邦機構通常需要在指定期限內完成修補或採取緩解措施。
CVE‑2026‑41091 係一個 Microsoft Defender 權限提升(Elevation of Privilege)漏洞。
漏洞成因係 Defender 在存取檔案之前錯誤解析連結(link following)。如果系統處理檔案時未正確處理符號連結或捷徑,就可能被利用去指向其他敏感位置。
主要特點包括:
一旦攻擊成功,攻擊者基本上可以完全控制系統,包括安裝程式、讀寫敏感資料或建立新管理員帳戶。
另一個漏洞 CVE‑2026‑45498 則屬於 拒絕服務(Denial‑of‑Service, DoS) 類型。
公開資料顯示,該漏洞可令 Microsoft Defender 出現服務中斷或無法正常運作的情況。
目前已知資訊包括:
雖然技術細節未完全公開,但這類漏洞嘅風險在於 令防毒系統失效,為後續惡意程式或攻擊鋪路。
CISA 在 2026 年 5 月 20 日 將包括上述兩個漏洞在內嘅七個漏洞加入 KEV 清單,因為已有證據顯示它們被攻擊者利用。
對於某些漏洞(例如 CVE‑2026‑45498),KEV 記錄列出:
根據 CISA 的 BOD 22‑01(Binding Operational Directive),美國聯邦政府機構需要在期限前修補漏洞或採取緩解措施,例如:
雖然這些要求主要針對政府機構,但 CISA 同時建議所有企業與組織優先處理 KEV 中的漏洞。
目前公開資料顯示,漏洞與以下 Defender 元件相關:
部分報告指出,漏洞影響 Malware Protection Engine 舊版本,例如 1.1.26040.8 之前版本。
不過,完整受影響版本範圍、更新部署細節以及完整技術分析目前仍未完全公開。
截至目前資料,仍有幾個重要技術資訊未完全披露:
安全機構通常會延遲公開部分技術細節,以避免攻擊者更容易複製攻擊。
2026 年 5 月曝光嘅兩個 Microsoft Defender 零日漏洞顯示,即使是內建安全工具亦可能成為攻擊入口:
對企業 IT 團隊而言,最重要的防禦措施仍然是 及時套用安全更新與維持 Defender 平台最新版本。
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
CISA 在 2026 年 5 月將兩個 Microsoft Defender 零日漏洞加入 KEV 目錄:CVE‑2026‑41091(權限提升)同 CVE‑2026‑45498(拒絕服務)。
CISA 在 2026 年 5 月將兩個 Microsoft Defender 零日漏洞加入 KEV 目錄:CVE‑2026‑41091(權限提升)同 CVE‑2026‑45498(拒絕服務)。 CVE‑2026‑41091 屬於高危漏洞,CVSS 3.1 評分 7.8,源於 Defender 在存取檔案前錯誤解析連結(link following)。
成功利用 CVE‑2026‑41091 可令低權限本地用戶升級至 SYSTEM 權限。