Important Notice: Security vulnerabilities of Microsoft (updated at 13 May 2026)
關於 Microsoft 的安全漏洞通告 (更新於 2026年5月13日)

資訊安全警示 Information Security Alert
To: All Users
As informed by the Cybersecurity Incident Alert and Response Centre (CARIC), Microsoft have recently released its May security update notice, there are 137 vulnerability updates this time.
This update mainly addresses vulnerabilities in the following components: Microsoft SharePoint Server, Windows Win32k, Windows GDI, and other related drivers.
Details of the vulnerabilities:
- Microsoft Word Remote Code Execution Vulnerability
For more details, please refer to: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-40361
- Microsoft Word Remote Code Execution Vulnerability
For more details, please refer to: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-40364
- Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
For more details, please refer to: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-33835
- Windows TCP/IP Local Elevation of Privilege Vulnerability
For more details, please refer to: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-33837
- Windows Win32k Elevation of Privilege Vulnerability
For more details, please refer to: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-35417
- Windows Win32k Elevation of Privilege Vulnerability
For more details, please refer to: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-33840
- Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
For more details, please refer to: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-35416
- Windows Kernel Elevation of Privilege Vulnerability
For more details, please refer to: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-40369
- Windows Kernel Elevation of Privilege Vulnerability
For more details, please refer to: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-33841
- Windows Remote Desktop Services Elevation of Privilege Vulnerability
For more details, please refer to: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-40398
- Windows Common Log File System Driver Elevation of Privilege Vulnerability
For more details, please refer to: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-40397
For more details about Microsoft May Updates, please refer to: https://msrc.microsoft.com/update-guide/releaseNote/2026-May
If the relevant affected products are used, please install the security updates released by Microsoft as soon as possible.
Reference
- How to download and install software in a secure manner?
- Basic Knowledge of Online Safety and Security
- Other Information Security Tips
Should you have any enquiries, please feel free to contact ICTO Help Desk.
ICTO Help Desk
Location : Room 2085, 2/F, Central Teaching Building (E5), eMap
Telephone : 8822 8600
email : icto.helpdesk@um.edu.mo
Information and Communication Technology Office
各位用戶:
資訊及通訊科技部接獲網絡安全事故預警及應急中心的通知,Microsoft 近日發布了 5月安全更新通告,此次包含了 137個漏洞更新。
此次釋出的更新主要涵蓋了以下組件: Microsoft SharePoint Server、 Windows Win32k、 Windows GDI 等驅動程序等漏洞。
漏洞詳情:
- Microsoft Word 遠程代碼執行漏洞
有關詳情可參考: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026- 40361
- Microsoft Word 遠程代碼執行漏洞
有關詳情可參考: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026- 40364
- Windows Cloud Files Mini Filter Driver 權限提升漏洞
有關詳情可參考: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026- 33835
- Windows TCP/IP 本地組件權限提升漏洞
有關詳情可參考:https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-33837
- Windows Win32k 權限提升漏洞
有關詳情可參考: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026- 35417
- Windows Win32k 權限提升漏洞
有關詳情可參考: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026- 33840
- Windows WinSock輔助功能驅動程序權限提升漏洞
有關詳情可參考: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026- 35416
- Windows 内核權限提升漏洞
有關詳情可參考: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026- 40369
- Windows 内核權限提升漏洞
有關詳情可參考: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026- 33841
- Windows 遠端桌面服務權限提升漏洞
有關詳情可參考: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026- 40398
- Windows 通用日誌文件系統驅動程序權限提升漏洞
有關詳情可參考: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026- 40397
Microsoft 5月更新有關詳情可參考:https://msrc.microsoft.com/update-guide/releaseNote/2026-May
倘有使用相關受影響產品,須盡快安裝由微軟公司釋出的安全更新。
參考資料
如有任何疑問,請聯絡資訊及通訊科技部服務中心。
服 務 中 心
位置 : 中央教學樓東5座(E5)二樓2085室 (電子地圖)
電話 : 8822 8600
電郵 : icto.helpdesk@um.edu.mo
資訊及通訊科技部