更新時間:2026/07/20 16:18:17
發佈時間:2026/07/20 16:18:17
TLP:
(White)
得對外公開散布,但不得違反著作權法等相關規定
更新說明:
一、漏洞說明[1][2][3]
Microsoft Active Directory Federation Services(AD FS)及SharePoint Server存在三項漏洞,說明如下:
1. CVE-2026-56155:AD FS存在存取控制粒度不足(Insufficient Granularity of Access Control)漏洞,已取得本機基本權限的攻擊者可利用該漏洞於本機提升至系統管理員權限。
2. CVE-2026-58644:Microsoft SharePoint Server存在不受信任資料反序列化(Deserialization of Untrusted Data)漏洞,已通過身分驗證且至少具網站擁有者權限的攻擊者,可透過網路於SharePoint Server寫入並執行任意程式碼。
3. CVE-2026-56164:Microsoft SharePoint Server存在關鍵功能缺少身分驗證(Missing Authentication for Critical Function)漏洞,允許未經身分驗證的攻擊者透過網路提升權限。
二、已揭露攻擊活動說明
1. Microsoft已確認三項漏洞均已遭利用。
2. CISA已納入漏洞利用清單。[4]
▶ 漏洞資訊
⌵
名稱:
CVE-2026-56155、CVE-2026-58644、CVE-2026-56164
描述:
使用版本:CVSS 3.1
分析分數:7.8、9.8、9.8
參考來源:Microsoft、NVD
▶ 影響平台
⌵
影響平台-系統:
1. CVE-2026-56155(Active Directory Federation Services,AD FS):
(1) Windows Server 2012(含Server Core installation)受影響,建議更新至Build 6.2.9200.26226或以上版本。
(2) Windows Server 2012 R2(含Server Core installation)受影響,建議更新至Build 6.3.9600.23291或以上版本。
(3) Windows Server 2016(含Server Core installation)及Windows 10 Version 1607受影響,建議更新至Build 10.0.14393.9339或以上版本。
(4) Windows Server 2019(含Server Core installation)及Windows 10 Version 1809受影響,建議更新至Build 10.0.17763.9020或以上版本。
(5) Windows Server 2022受影響,建議更新至Build 10.0.20348.5386或以上版本。
(6) Windows Server 2025(含Server Core installation)受影響,建議更新至Build 10.0.26100.33158或以上版本。
2. CVE-2026-58644及CVE-2026-56164(Microsoft SharePoint Server):
(1) Microsoft SharePoint Enterprise Server 2016受影響,建議更新至16.0.5561.1001或以上版本。
(2) Microsoft SharePoint Server 2019受影響,建議更新至16.0.10417.20175或以上版本。
(3) Microsoft SharePoint Server Subscription Edition受影響,建議更新至16.0.19725.20434或以上版本。
▶ 建議措施
⌵
1. 官方已發布修補程式,建議會員依據單位內漏洞管理機制進行相關作業。
2. 針對AD FS環境,修補後建議依Microsoft《AD FS Distributed Key Manager container ACL hardening》指引完成相關安全強化作業。[5]
3. 針對SharePoint Server環境,建議啟用Antimalware Scan Interface(AMSI),並將AMSI Request Body Scan設定為Full Mode,以降低遭利用風險。[6]
▶ 參考資訊
⌵
| 編號 | 網址 | 說明 |
|---|---|---|
| 1 | https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-56155 | Microsoft(CVE-2026-56155) |
| 2 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644 | Microsoft(CVE-2026-58644) |
| 3 | https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164 | Microsoft(CVE-2026-56164) |
| 4 | https://www.cisa.gov/known-exploited-vulnerabilities-catalog | CISA |
| 5 | https://support.microsoft.com/en-us/servicing/os/windows/docs/2026/07/kb5121391-cve-2026-56155-ad-fs-dkm-container-acl-hardening | Microsoft(AD FS指引) |
| 6 | https://learn.microsoft.com/zh-tw/sharepoint/security-for-sharepoint-server/configure-amsi-integration | Microsoft(AMSI設定) |
情資編號:
FISAC-200-202607-0005
系統目錄:
資安漏洞
資安類別:
漏洞公告 /
影響等級:
3
關鍵字:
弱點漏洞