[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/microsoft-cve-2022-26925-etc/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/microsoft-cve-2022-26925-etc/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/ "主なサイバー脅威")
* [脆弱性](https://unit42.paloaltonetworks.com/ja/category/vulnerabilities-ja/ "脆弱性")  
  [脆弱性](https://unit42.paloaltonetworks.com/ja/category/vulnerabilities-ja/)

# 脅威に関する情報: Microsoft製品の重大脆弱性(CVE-2022-26809、CVE-2022-26923、CVE-2022-26925)

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 4 分で読めます  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/ja/product-category/advanced-threat-prevention-ja/ "Advanced Threat Prevention")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/ja/product-category/cortex-xdr-ja/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/ja/product-category/next-generation-firewall-ja/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Chao Lei](https://unit42.paloaltonetworks.com/ja/author/chao-lei/)
  * [Tao Yan](https://unit42.paloaltonetworks.com/ja/author/tao-yan/)
  * [Haozhe Zhang](https://unit42.paloaltonetworks.com/ja/author/haozhe-zhang/)
  * [Qi Deng](https://unit42.paloaltonetworks.com/ja/author/qi-deng/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2022年7月27日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [脆弱性](https://unit42.paloaltonetworks.com/ja/category/vulnerabilities-ja/)
  * [主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [CVE-2022-26809](https://unit42.paloaltonetworks.com/ja/tag/cve-2022-26809-ja/)
  * [CVE-2022-26923](https://unit42.paloaltonetworks.com/ja/tag/cve-2022-26923-ja/)
  * [CVE-2022-26925](https://unit42.paloaltonetworks.com/ja/tag/cve-2022-26925-ja/)
  * [Microsoft](https://unit42.paloaltonetworks.com/ja/tag/microsoft-ja/)
  * [Microsoft Windows](https://unit42.paloaltonetworks.com/ja/tag/microsoft-windows-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/microsoft-cve-2022-26925-etc/?pdf=download&lg=ja&_wpnonce=5f0cc26d8b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/microsoft-cve-2022-26925-etc/?pdf=print&lg=ja&_wpnonce=5f0cc26d8b "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](<mailto:?subject=脅威に関する情報:%20Microsoft製品の重大脆弱性(CVE-2022-26809、CVE-2022-26923、CVE-2022-26925)&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fmicrosoft-cve-2022-26925-etc%2F> "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fmicrosoft-cve-2022-26925-etc%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](<https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fmicrosoft-cve-2022-26925-etc%2F&title=脅威に関する情報:%20Microsoft製品の重大脆弱性(CVE-2022-26809、CVE-2022-26923、CVE-2022-26925)> "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](<https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fmicrosoft-cve-2022-26925-etc%2F&text=脅威に関する情報:%20Microsoft製品の重大脆弱性(CVE-2022-26809、CVE-2022-26923、CVE-2022-26925)> "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fmicrosoft-cve-2022-26925-etc%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](<https://mastodon.social/share?text=脅威に関する情報:%20Microsoft製品の重大脆弱性(CVE-2022-26809、CVE-2022-26923、CVE-2022-26925)%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fmicrosoft-cve-2022-26925-etc%2F> "Share in Mastodon")

## 概要

Microsoftは2022年[4月](https://msrc.microsoft.com/update-guide/releaseNote/2022-Apr)および[5月](https://msrc.microsoft.com/update-guide/releaseNote/2022-May)のセキュリティ更新プログラムで、以下の脆弱性を含む複数の重大な脆弱性に対する修正を提供しました。

* [CVE-2022-26809](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26809): 未許可の攻撃者がこの脆弱性を利用し、特別に細工したリモートプロシージャコール (RPC) を送信することにより、リモートから脆弱なデバイス上で任意のコードを実行できる可能性があります。
* [CVE-2022-26923](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26923):「Active Directory Certificate Services」のサーバー ロールがインストールされたデフォルトの Active Directory環境において、権限の低いユーザーがドメイン管理者に権限を昇格できます。
* [CVE-2022-26925](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26925): 未認証の攻撃者が、Windows NT LAN Manager (NTLM) セキュリティ プロトコルを介し、ドメイン コントローラをリモートから悪用して強制的に認証させることができます。

これらの問題に対処するセキュリティ更新プログラムの適用を強くお勧めします。

パロアルトネットワークスのお客様は、[脅威防御](https://www.paloaltonetworks.jp/network-security/threat-prevention)セキュリティサブスクリプションをもつ[次世代](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)ファイアウォールで保護されています。また、[Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)その他の製品による保護を受けています。

|----------|------------------------------------------------|
| 本稿で扱うCVE | CVE-2022-26809, CVE-2022-26923, CVE-2022-26925 |

## 目次

[影響を受けるバージョン](#post-124224-_5hnyzweu5uik)  
[CVE-2022-26809、CVE-2022-26923、CVE-2022-26925の緩和策](#post-124224-_2vsktbo0pyu4)  
[エクスプロイト](#post-124224-_omrajredovy)  
[結論](#post-124224-_xrtic6xk9oin)  
[追加リソース](#post-124224-_570cbe1pdhwx)

## 影響を受けるバージョン

### CVE-2022-26809

Microsoft Windows オペレーティングシステムの以下のバージョンはCVE-2022-26809に対し脆弱です。

Windows 7 for 32-bit systems Service Pack 1  
Windows 7 for x64-based systems Service Pack 1  
Windows 8.1 for 32-bit systems  
Windows RT 8.1  
Windows 8.1 for x64-based systems  
Windows 10 Version 20H2 for ARM64-based systems  
Windows 10 Version 1909 for ARM64-based systems  
Windows 10 Version 1809 for x64-based systems  
Windows 10 for 32-bit systems  
Windows 10 Version 21H2 for x64-based systems  
Windows 10 Version 21H2 for ARM64-based systems  
Windows 10 Version 21H2 for 32-bit systems  
Windows 10 Version 1809 for 32-bit systems  
Windows 10 Version 21H1 for 32-bit systems  
Windows 10 Version 21H1 for ARM64-based systems  
Windows 10 Version 21H1 for x64-based systems  
Windows 10 Version 20H2 for 32-bit systems  
Windows 10 Version 20H2 for x64-based systems  
Windows 10 Version 1607 for x64-based systems  
Windows 10 Version 1607 for 32-bit systems  
Windows 10 for x64-based systems  
Windows 10 Version 1909 for x64-based systems  
Windows 10 Version 1909 for 32-bit systems  
Windows 10 Version 1809 for ARM64-based systems  
Windows 11 for ARM64-based systems  
Windows 11 for x64-based systems  
Windows Server 2008 R2 for x64-based systems Service Pack 1 (Server Core installation)  
Windows Server 2008 R2 for x64-based systems Service Pack 1  
Windows Server 2008 for x64-based systems Service Pack 2 (Server Core installation)  
Windows Server 2008 for x64-based systems Service Pack 2  
Windows Server 2008 for 32-bit systems Service Pack 2 (Server Core installation)  
Windows Server 2008 for 32-bit systems Service Pack 2  
Windows Server 2012 R2 (Server Core installation)  
Windows Server 2012 R2  
Windows Server 2012 (Server Core installation)  
Windows Server 2012  
Windows Server 2016  
Windows Server 2016 (Server Core installation)  
Windows Server, version 20H2 (Server Core Installation)  
Windows Server 2019 (Server Core installation)  
Windows Server 2019  
Windows Server 2022 (Server Core installation)  
Windows Server 2022

### CVE-2022-26923

Microsoft Windows オペレーティングシステムの以下のバージョンはCVE-2022-26923に対し脆弱です。

Windows Server 2012 R2 (Server Core installation)  
Windows Server 2012 R2  
Windows RT 8.1  
Windows 8.1 for x64-based systems  
Windows 8.1 for 32-bit systems  
Windows Server 2016 (Server Core installation)  
Windows Server 2016  
Windows 10 Version 1607 for x64-based systems  
Windows 10 Version 1607 for 32-bit systems  
Windows 10 for x64-based systems  
Windows 10 for 32-bit systems  
Windows 10 Version 21H2 for x64-based systems  
Windows 10 Version 21H2 for ARM64-based systems  
Windows 10 Version 21H2 for 32-bit systems  
Windows 11 for ARM64-based systems  
Windows 11 for x64-based systems  
Windows Server, version 20H2 (Server Core Installation)  
Windows 10 Version 20H2 for ARM64-based systems  
Windows 10 Version 20H2 for 32-bit systems  
Windows 10 Version 20H2 for x64-based systems  
Windows Server 2022 (Server Core installation)  
Windows Server 2022  
Windows 10 Version 21H1 for 32-bit systems  
Windows 10 Version 21H1 for ARM64-based systems  
Windows 10 Version 21H1 for x64-based systems  
Windows 10 Version 1909 for ARM64-based systems  
Windows 10 Version 1909 for x64-based systems  
Windows 10 Version 1909 for 32-bit systems  
Windows Server 2019 (Server Core installation)  
Windows Server 2019  
Windows 10 Version 1809 for ARM64-based systems  
Windows 10 Version 1809 for x64-based systems  
Windows 10 Version 1809 for 32-bit systems

### CVE-2022-26925

Microsoft Windows オペレーティングシステムの以下のバージョンはCVE-2022-26925に対し脆弱です。

Windows Server 2012 R2 (Server Core installation)  
Windows Server 2012 R2  
Windows Server 2012 (Server Core installation)  
Windows Server 2012  
Windows Server 2008 R2 for x64-based systems Service Pack 1 (Server Core installation)  
Windows Server 2008 R2 for x64-based systems Service Pack 1  
Windows Server 2008 for x64-based systems Service Pack 2 (Server Core installation)  
Windows Server 2008 for x64-based systems Service Pack 2  
Windows Server 2008 for 32-bit systems Service Pack 2 (Server Core installation)  
Windows Server 2008 for 32-bit systems Service Pack 2  
Windows RT 8.1  
Windows 8.1 for x64-based systems  
Windows 8.1 for 32-bit systems  
Windows 7 for x64-based systems Service Pack 1  
Windows 7 for 32-bit systems Service Pack 1  
Windows Server 2016 (Server Core installation)  
Windows Server 2016  
Windows 10 Version 1607 for x64-based systems  
Windows 10 Version 1607 for 32-bit systems  
Windows 10 for x64-based systems  
Windows 10 for 32-bit systems  
Windows 10 Version 21H2 for x64-based systems  
Windows 10 Version 21H2 for ARM64-based systems  
Windows 10 Version 21H2 for 32-bit systems  
Windows 11 for ARM64-based systems  
Windows 11 for x64-based systems  
Windows Server, version 20H2 (Server Core Installation)  
Windows 10 Version 20H2 for ARM64-based systems  
Windows 10 Version 20H2 for 32-bit systems  
Windows 10 Version 20H2 for x64-based systems  
Windows Server 2022 (Server Core installation)  
Windows Server 2022  
Windows 10 Version 21H1 for 32-bit systems  
Windows 10 Version 21H1 for ARM64-based systems  
Windows 10 Version 21H1 for x64-based systems  
Windows 10 Version 1909 for ARM64-based systems  
Windows 10 Version 1909 for x64-based systems  
Windows 10 Version 1909 for 32-bit systems  
Windows Server 2019 (Server Core installation)  
Windows Server 2019  
Windows 10 Version 1809 for ARM64-based systems  
Windows 10 Version 1809 for x64-based systems  
Windows 10 Version 1809 for 32-bit systems

## CVE-2022-26809、CVE-2022-26923、CVE-2022-26925の緩和策

Microsoftは[CVE-2022-26809](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-26809)、[CVE-2022-26923](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-26923)、[CVE-2022-26925](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-26925)用の更新プログラムをすでに公開しています。これら3つの脆弱性とエクスプロイトの詳細はすべて公開されており、CVE-2022-26925はすでに実際の悪用が確認されています。なるべく早くシステムに更新プログラムを適用することをお勧めします。

## エクスプロイト

### CVE-2022-26809 -- RPCリモートコード実行の脆弱性

Microsoftの4月のセキュリティ更新プログラムにはリモートコード実行につながりうる深刻なRPCの脆弱性が含まれています。この脆弱性が悪用されると、攻撃者はリモートからの攻撃対象領域を取得し、Windows SMBサービスをリモートから攻撃してコードを実行できるようになります。この脅威はWindows SMB サービスに限定されません。脆弱なRPCコンポーネントを使うほかのサービスにも影響する可能性があります。

2022年5月1日に私たちはGitHub上にPoC（概念実証コード: Proof of Concept）が公開されたことを確認しています。同リサーチャーはCVE-2022-26809の分析を行い、脆弱な関数OSF\_SCALL::GetCoalescedBufferをトリガーするPoCを作成しました。このPoCは[Microsoft](https://github.com/microsoft/Windows-classic-samples/blob/main/Samples/Win7Samples/netds/rpc/hello)のRPCサンプルコード「Hello」をベースに作成されたものです。RPCを使うプログラム インターフェイスにはMicrosoft Interface Definition Language (MIDL) による定義とMIDLコンパイラによるコンパイルが必要とされます。このため当該リサーチャーはIDLファイルに新たなパイプ型と複数の関数を追加していました。追加の理由は脆弱性のトリガーにサーバー側でのパイプの利用が必要なためです。関連する変更を図1に示します。
![RPCを使うプログラム インターフェイスは、Microsoft Interface Definition Language (MIDL) による定義とMIDLコンパイラによるコンパイルが必要とされます。このため、当該リサーチャーはIDLファイルに新たなパイプ型と複数の関数を追加しました。これが追加された理由は、脆弱性のトリガーにサーバー側でのパイプの利用が必要なためです。関連する変更をこの図に示します。](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/07/word-image-112.png) 図1. IDLファイルの変更

このPoCクライアントはデータ送信にimpacket.dcerpc.v5.rpcrtを利用します。さらにこのリサーチャーはrpcrtライブラリのパケット処理ロジックを変更していました。このPoCはカスタマイズされたRPCサーバーでのみ実行可能で、本脆弱性のエクスプロイト成功にはサーバー側に特定の設定が必要ですが、攻撃者がこのPoCを変更してデフォルト状態のWindowsサービスに対しても実行可能なエクスプロイトを作成する可能性はあります。私たちはCVE-2022-26809に対する修正プログラムを早急に適用することを強く推奨します。

### CVE-2022-26923 -- Active Directoryドメインサービスにおける特権昇格の脆弱性

この脆弱性により「Active Directory Certificate Services」のサーバー ロールがインストールされたデフォルトの Active Directory環境において、権限の低いユーザーがドメイン管理者に権限を昇格できます。これは偽のドメインコントローラdNSHostNameを使って有効な証明書を取得し、その証明書をこの偽ドメインコントローラに対して認証することでドメインコントローラ権限を取得するロジック上の問題です。Microsoftは5月のセキュリティ更新でCVE-2022-26923を修正しましたが、当該の脆弱性とエクスプロイトの詳細は一般公開されています。なるべく早く更新プログラムを適用することをお勧めします。

### CVE-2022-26925 -- Windows LSA のなりすましの脆弱性

この脆弱性は、未認証の攻撃者がLSARPCインタフェース上のメソッドを呼び出し、NTLMを使ってドメインコントローラに対し攻撃者を認証するよう強要できるというものです。NTLMリレー攻撃でNTLMハッシュを取得した攻撃者は、漏えいしたドメインコントローラのNTLMハッシュを使ってさらにシステムを攻撃可能です。CVE-2022-26925は実際の悪用が確認されておりエクスプロイトも公開されています。Microsoftは当該脆弱性を5月のセキュリティ更新で修正済みです。なるべく早く更新プログラムを適用することをお勧めします。

## 結論

CVE-2022-26809は広く攻撃に悪用される可能性があることから、私たちは現在も引き続き集中的にこの脆弱性を監視しています。現在入手可能な情報からこの脆弱性は将来的に深刻な影響を及ぼす可能性があります。RPCはWindowsやWindows Serverの各種バージョンで広く利用されていますし、脆弱性のあるrpcrt4.dllはMicrosoftのサービスのほかにもさまざまなアプリケーションで利用されています。CVE-2022-26923とCVE-2022-26925のエクスプロイトはすでに一般公開されていることからこれらの脆弱性が攻撃者に悪用されるのは時間の問題です。ユーザーはこれらの脆弱性からの保護に必要なすべての措置を講じてください。

脅威防御サブスクリプションが有効な弊社NGFW製品はこれらの脆弱性に関連する攻撃トラフィックをブロックできます。

* CVE-2022-26809のカバレッジ: 脅威ID 92490 (Application and Threat content update 8557)
* CVE-2022-26923のカバレッジ: 脅威ID 92548 (Application and Threat content update 8568)
* CVE-2022-26925のカバレッジ: 脅威ID 92549 (Application and Threat content update 8568)

Cortex製品をご利用中のお客様は、CVE-2022-26923およびCVE-2022-26925から保護されています。

## 追加リソース

[リモート プロシージャ コール ランタイムのリモートでコードが実行される脆弱性](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26809) -- Microsoft  
[Active Directory Domain Services Elevation of Privilege Vulnerability](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26923) -- Microsoft  
[Certifried: Active Directory Domain Privilege Escalation (CVE-2022--26923)](https://research.ifcr.dk/certifried-active-directory-domain-privilege-escalation-cve-2022-26923-9e098fe298f4) -- IFCR  
[PetitPotam](https://github.com/topotam/PetitPotam) -- GitHub  
[Microsoft fixes new PetitPotam Windows NTLM Relay attack vector](https://www.bleepingcomputer.com/news/security/microsoft-fixes-new-petitpotam-windows-ntlm-relay-attack-vector/) -- BleepingComputer  
[Windows LSA のなりすましの脆弱性](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26925) -- Microsoft  
[リモート プロシージャ呼び出し (RPC)](https://docs.microsoft.com/ja-jp/windows/win32/rpc/rpc-start-page) -- Microsoft
トップに戻る

### タグ

* [CVE-2022-26809](https://unit42.paloaltonetworks.com/ja/tag/cve-2022-26809-ja/ "CVE-2022-26809")
* [CVE-2022-26923](https://unit42.paloaltonetworks.com/ja/tag/cve-2022-26923-ja/ "CVE-2022-26923")
* [CVE-2022-26925](https://unit42.paloaltonetworks.com/ja/tag/cve-2022-26925-ja/ "CVE-2022-26925")
* [Microsoft](https://unit42.paloaltonetworks.com/ja/tag/microsoft-ja/ "Microsoft")
* [Microsoft Windows](https://unit42.paloaltonetworks.com/ja/tag/microsoft-windows-ja/ "Microsoft Windows")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:攻撃者は注目のゼロデイをすばやく利用: 2022 Unit 42 インシデント対応レポートからの知見](https://unit42.paloaltonetworks.com/ja/incident-response-report/ "攻撃者は注目のゼロデイをすばやく利用: 2022 Unit 42 インシデント対応レポートからの知見")

### 目次

* 

### 関連記事

* [Microsoft WSUSのリモートコード実行の脆弱性（CVE-2025-59287）、実環境における活発な悪用を確認（11月3日更新）](https://unit42.paloaltonetworks.com/ja/microsoft-cve-2025-59287/ "article - table of contents")
* [Jingle Thief: クラウドベースのギフトカード詐欺キャンペーンの実態](https://unit42.paloaltonetworks.com/ja/cloud-based-gift-card-fraud-campaign/ "article - table of contents")
* [モデル名前空間の再利用テクニック: AIサプライチェーンの基本的側面を誤用する](https://unit42.paloaltonetworks.com/ja/model-namespace-reuse/ "article - table of contents")

## 関連項目 リソース

![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年5月5日 [#### Copy Fail:ここ数年で最も深刻なLinuxの脅威について必要な知識](https://unit42.paloaltonetworks.com/ja/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/ja/tag/containers-ja/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/ja/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/ja/tag/kubernetes-ja/ "Kubernetes")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/cve-2026-31431-copy-fail/ "Copy Fail:ここ数年で最も深刻なLinuxの脅威について必要な知識")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月19日 [#### BeyondTrustの深刻な脆弱性（CVE-2026-1731）の悪用においてVShellおよびSparkRATを確認](https://unit42.paloaltonetworks.com/ja/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/ja/tag/bash-ja/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/ja/tag/cve-2026-1731/ "CVE-2026-1731")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/beyondtrust-cve-2026-1731/ "BeyondTrustの深刻な脆弱性（CVE-2026-1731）の悪用においてVShellおよびSparkRATを確認")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月17日 [#### 野放し状態で悪用されているIvanti EPMMの深刻な脆弱性](https://unit42.paloaltonetworks.com/ja/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/ja/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/ja/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/ja/tag/ivanti-ja/ "Ivanti")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/ivanti-cve-2026-1281-cve-2026-1340/ "野放し状態で悪用されているIvanti EPMMの深刻な脆弱性")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月30日 [#### SCADAシステムに存在する特権ファイルシステムの脆弱性](https://unit42.paloaltonetworks.com/ja/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/ja/tag/privilege-escalation-ja/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/ja/tag/scada/ "SCADA")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iconics-suite-cve-2025-0921/ "SCADAシステムに存在する特権ファイルシステムの脆弱性")  
  ![Pictorial representation of remote code execution in AI and machine learning libraries. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/05_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月13日 [#### 最新のAI/MLフォーマットとライブラリによるリモート コード実行](https://unit42.paloaltonetworks.com/ja/rce-vulnerabilities-in-ai-python-libraries/)

* [Apple](https://unit42.paloaltonetworks.com/ja/tag/apple-ja/ "Apple")

* [CVE-2025-23304](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-23304/ "CVE-2025-23304")

* [CVE-2026-22584](https://unit42.paloaltonetworks.com/ja/tag/cve-2026-22584/ "CVE-2026-22584")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/rce-vulnerabilities-in-ai-python-libraries/ "最新のAI/MLフォーマットとライブラリによるリモート コード実行")  
  ![Pictorial representation of MongoBleed, CVE-2025-14847. Digital image featuring a glowing padlock icon superimposed on a background of streaming blue binary code, symbolizing cybersecurity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/AdobeStock_233494953-786x429.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年1月13日 [#### 脅威ブリーフ: MongoDB の脆弱性 (CVE-2025-14847)](https://unit42.paloaltonetworks.com/ja/mongobleed-cve-2025-14847/)

* [CVE-2025-14847](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-14847/ "CVE-2025-14847")

* [MongoDB](https://unit42.paloaltonetworks.com/ja/tag/mongodb-ja/ "MongoDB")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/mongobleed-cve-2025-14847/ "脅威ブリーフ: MongoDB の脆弱性 (CVE-2025-14847)")  
  ![Pictorial representation of CVE-2025-55182 (React) and CVE-2025-66478 (Next.js). Close-up of a digital display on electronic equipment with illuminated text reading "SYSTEM HACKED" in red, set against a blurred background of blue and red lights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/02_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2025年12月12日 [#### React Server Components における重大な脆弱性の悪用 (12月12日更新)](https://unit42.paloaltonetworks.com/ja/cve-2025-55182-react-and-cve-2025-66478-next/)

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [CVE-2025-66478](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-66478-ja/ "CVE-2025-66478")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/cve-2025-55182-react-and-cve-2025-66478-next/ "React Server Components における重大な脆弱性の悪用 (12月12日更新)")  
  ![Pictorial representation of an authentication coercion attack. Panoramic view of a city skyline at night, featuring vibrant light beams from skyscrapers and a deep blue sky.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年11月10日 [#### 新たなアップデート。進化し続ける強制認証テクニック](https://unit42.paloaltonetworks.com/ja/authentication-coercion/)

* [Mimikatz](https://unit42.paloaltonetworks.com/ja/tag/mimikatz-ja/ "Mimikatz")

* [PrintNightmare](https://unit42.paloaltonetworks.com/ja/tag/printnightmare-ja/ "PrintNightmare")

* [Privilege escalation](https://unit42.paloaltonetworks.com/ja/tag/privilege-escalation-ja/ "privilege escalation")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/authentication-coercion/ "新たなアップデート。進化し続ける強制認証テクニック")  
  ![Pictorial representation of LANDFALL spyware. An illustration of a glowing red warning icon centered on a detailed blue circuit board background, representing a vulnerability in Samsung Galaxy devices.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/09_Nation-State-cyberattacks_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2025年11月7日 [#### LANDFALL: Samsungデバイスを標的とするエクスプロイト チェーンで使用される、新種の商用グレードAndroidスパイウェア](https://unit42.paloaltonetworks.com/ja/landfall-is-new-commercial-grade-android-spyware/)

* [Android](https://unit42.paloaltonetworks.com/ja/tag/android-ja/ "Android")

* [Apple](https://unit42.paloaltonetworks.com/ja/tag/apple-ja/ "Apple")

* [CVE-2025-21042](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-21042-ja/ "CVE-2025-21042")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/landfall-is-new-commercial-grade-android-spyware/ "LANDFALL: Samsungデバイスを標的とするエクスプロイト チェーンで使用される、新種の商用グレードAndroidスパイウェア")  
  ![Pictorial representation of CVE-2025-59287. Digital image of a glowing padlock symbol representing cybersecurity on a network grid with blue and orange lights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/08_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2025年11月3日 [#### Microsoft WSUSのリモートコード実行の脆弱性（CVE-2025-59287）、実環境における活発な悪用を確認（11月3日更新）](https://unit42.paloaltonetworks.com/ja/microsoft-cve-2025-59287/)

* [CVE-2025-59287](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-59287-ja/ "CVE-2025-59287")

* [Microsoft](https://unit42.paloaltonetworks.com/ja/tag/microsoft-ja/ "Microsoft")

* [Microsoft Vulnerability](https://unit42.paloaltonetworks.com/ja/tag/microsoft-vulnerability-ja/ "Microsoft Vulnerability")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/microsoft-cve-2025-59287/ "Microsoft WSUSのリモートコード実行の脆弱性（CVE-2025-59287）、実環境における活発な悪用を確認（11月3日更新）")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
