{"id":2072,"date":"2026-10-01T07:18:36","date_gmt":"2026-10-01T00:18:36","guid":{"rendered":"https:\/\/vncybers.vn\/ho-so-cve-2026-73570-email-kiem-soat-may-chu-zimbra\/"},"modified":"2026-10-01T07:18:36","modified_gmt":"2026-10-01T00:18:36","slug":"cve-2026-73570-profile-email-to-zimbra-server-takeover","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/ho-so-cve-2026-73570-email-kiem-soat-may-chu-zimbra\/","title":{"rendered":"CVE-2026-73570 records: From an email to Zimbra server control"},"content":{"rendered":"<p><strong>CVE-2026-73570<\/strong> cho th\u1ea5y m\u1ed9t email \u0111\u01b0\u1ee3c t\u1ea1o \u0111\u1eb7c bi\u1ec7t c\u00f3 th\u1ec3 tr\u1edf th\u00e0nh \u0111i\u1ec3m kh\u1edfi \u0111\u1ea7u c\u1ee7a chu\u1ed7i x\u00e2m nh\u1eadp nghi\u00eam tr\u1ecdng: th\u1ef1c thi l\u1ec7nh t\u1eeb xa, c\u00e0i web shell, \u0111\u00e1nh c\u1eafp b\u00ed m\u1eadt x\u00e1c th\u1ef1c, \u0111\u1ecdc d\u1eef li\u1ec7u h\u1ed9p th\u01b0 v\u00e0 di chuy\u1ec3n ngang gi\u1eefa c\u00e1c m\u00e1y ch\u1ee7 Zimbra. Microsoft ghi nh\u1eadn ho\u1ea1t \u0111\u1ed9ng khai th\u00e1c t\u1ea1i nhi\u1ec1u khu v\u1ef1c v\u00e0 ng\u00e0nh ngh\u1ec1, trong khi danh t\u00ednh nh\u00f3m \u0111\u1ee9ng sau v\u1eabn ch\u01b0a \u0111\u01b0\u1ee3c x\u00e1c \u0111\u1ecbnh.<\/p>\n<h2>Where is the gap?<\/h2>\n<p>CVE-2026-73570 l\u00e0 l\u1ed7i ch\u00e8n l\u1ec7nh h\u1ec7 \u0111i\u1ec1u h\u00e0nh kh\u00f4ng c\u1ea7n x\u00e1c th\u1ef1c trong Zimbra Collaboration Suite (ZCS), \u0111\u01b0\u1ee3c ch\u1ea5m 8,9 \u0111i\u1ec3m CVSS. \u0110i\u1ec1u ki\u1ec7n d\u1ec5 b\u1ecb khai th\u00e1c l\u00e0 m\u00e1y ch\u1ee7 c\u00e0i g\u00f3i t\u00f9y ch\u1ecdn <code>zimbra-snmp<\/code> v\u00e0 b\u1eadt th\u00f4ng b\u00e1o SNMP. K\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3 k\u00edch ho\u1ea1t l\u1ed7i b\u1eb1ng m\u1ed9t y\u00eau c\u1ea7u SMTP \u0111\u01b0\u1ee3c ch\u1ebf t\u1ea1o \u0111\u1eb7c bi\u1ec7t, kh\u00f4ng c\u1ea7n \u0111\u0103ng nh\u1eadp hay t\u01b0\u01a1ng t\u00e1c c\u1ee7a ng\u01b0\u1eddi d\u00f9ng.<\/p>\n<p>Zimbra fixed the bug in version 10.1.20 released on July 20, 2026. However, Microsoft data shows that suspicious activity appeared between the date of the patch's release and August 13, when the vulnerability was publicly disclosed.<\/p>\n<h2>Extraction duration<\/h2>\n<ul>\n<li><strong>20\/7\/2026:<\/strong> Zimbra ph\u00e1t h\u00e0nh phi\u00ean b\u1ea3n 10.1.20 ch\u1ee9a b\u1ea3n s\u1eeda l\u1ed7i.<\/li>\n<li><strong>28\/7\u20137\/8\/2026:<\/strong> hai c\u00f4ng c\u1ee5 qu\u00e9t ngo\u00e0i b\u0103ng ri\u00eang bi\u1ec7t d\u00f2 \u0111\u01b0\u1eddng d\u1eabn ch\u00e8n l\u1ec7nh \u0111\u1ec3 x\u00e1c nh\u1eadn kh\u1ea3 n\u0103ng th\u1ef1c thi.<\/li>\n<li><strong>13\/8\/2026:<\/strong> th\u00f4ng tin l\u1ed7 h\u1ed5ng \u0111\u01b0\u1ee3c c\u00f4ng b\u1ed1.<\/li>\n<li><strong>Th\u00e1ng 8\/2026:<\/strong> CERT Polska c\u1ea3nh b\u00e1o v\u1ec1 khai th\u00e1c th\u1ef1c t\u1ebf; CISA sau \u0111\u00f3 \u0111\u01b0a CVE v\u00e0o danh m\u1ee5c Known Exploited Vulnerabilities.<\/li>\n<li><strong>30\/9\/2026:<\/strong> Microsoft c\u00f4ng b\u1ed1 ph\u00e2n t\u00edch chi ti\u1ebft chu\u1ed7i t\u1ea5n c\u00f4ng v\u00e0 c\u00e1c t\u1ea3i tr\u1ecdng chuy\u00ean bi\u1ec7t cho Zimbra.<\/li>\n<\/ul>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/10\/zimbra-inline.jpg\" alt=\"Attack chain targeting Zimbra servers through CVE-2026-73570\"\/><figcaption>Mail servers are high-value targets because they centralize data and authentication secrets. Image from the original report: The Hacker News.<\/figcaption><\/figure>\n<h2>From service account to web shell<\/h2>\n<p>Sau khi khai th\u00e1c th\u00e0nh c\u00f4ng, l\u1ec7nh ban \u0111\u1ea7u ch\u1ea1y d\u01b0\u1edbi t\u00e0i kho\u1ea3n d\u1ecbch v\u1ee5 <code>zimbra<\/code>. K\u1ebb t\u1ea5n c\u00f4ng tri\u1ec3n khai nhi\u1ec1u web shell JSP trong c\u00e1c \u0111\u01b0\u1eddng d\u1eabn Jetty v\u00e0 mailboxd \u0111\u1ec3 d\u1ef1 ph\u00f2ng, t\u1ea3i th\u00eam m\u00e3 \u0111\u1ed9c b\u1eb1ng <code>wget<\/code> ho\u1eb7c <code>curl<\/code>, r\u1ed3i m\u1edf reverse shell t\u01b0\u01a1ng t\u00e1c. M\u1ed9t s\u1ed1 chu\u1ed7i s\u1eed d\u1ee5ng cron, systemd ho\u1eb7c <code>memfd_create<\/code> \u0111\u1ec3 duy tr\u00ec th\u1ef1c thi \u0111\u1ecbnh k\u1ef3 hay ch\u1ea1y tr\u1ef1c ti\u1ebfp trong b\u1ed9 nh\u1edb.<\/p>\n<p>Notably, the agent sometimes temporarily opens the write permission for the public folder, puts the web shell in and then restores the old permission. This makes it difficult to detect changes to basic file permissions.<\/p>\n<h2>Escalate privilege and move sideways<\/h2>\n<p>Microsoft quan s\u00e1t k\u1ef9 thu\u1eadt s\u1eeda <code>\/etc\/pam.d\/sudo<\/code> \u0111\u1ec3 c\u1ea5p cho t\u00e0i kho\u1ea3n zimbra quy\u1ec1n sudo kh\u00f4ng gi\u1edbi h\u1ea1n v\u00e0 kh\u00f4ng c\u1ea7n m\u1eadt kh\u1ea9u. Nh\u00f3m t\u1ea5n c\u00f4ng c\u00f2n t\u1ea1o d\u1ecbch v\u1ee5 <code>zimlog.service<\/code> nh\u1eb1m t\u1ef1 kh\u1edfi ch\u1ea1y c\u00f9ng h\u1ec7 th\u1ed1ng.<\/p>\n<p>Sau \u0111\u00f3, ch\u00fang d\u00f9ng <code>zmprov<\/code> \u0111\u1ec3 l\u1eadp b\u1ea3n \u0111\u1ed3 c\u1ee5m Zimbra, t\u00ecm m\u00e1y ch\u1ee7 mailbox v\u00e0 MTA, \u0111\u1ed3ng th\u1eddi ki\u1ec3m tra kh\u00f3a SSH s\u1eb5n c\u00f3 t\u1ea1i <code>\/opt\/zimbra\/.ssh\/zimbra_identity<\/code>. Kh\u00f3a n\u00e0y c\u00f9ng c\u00f4ng c\u1ee5 rsync c\u00f3 th\u1ec3 gi\u00fap chuy\u1ec3n web shell v\u00e0 t\u1eadp l\u1ec7nh sang c\u00e1c n\u00fat tin c\u1eady kh\u00e1c.<\/p>\n<h2>Target is a centralized authentication secret<\/h2>\n<p>Thay v\u00ec ch\u1ec9 s\u0103n m\u1eadt kh\u1ea9u t\u1eebng h\u1ed9p th\u01b0, k\u1ebb t\u1ea5n c\u00f4ng ch\u1ea1y <code>zmlocalconfig -s<\/code> \u0111\u1ec3 thu th\u1eadp b\u00ed m\u1eadt d\u1ecbch v\u1ee5 t\u1eadp trung. C\u00e1c th\u00f4ng tin n\u00e0y \u0111\u01b0\u1ee3c d\u00f9ng truy v\u1ea5n LDAP v\u00e0 l\u1ea5y nh\u1eefng thu\u1ed9c t\u00ednh gi\u00e1 tr\u1ecb cao nh\u01b0 <code>zimbraPreAuthKey<\/code>, <code>zimbraAuthTokenKey<\/code> and <code>zimbraTwoFactorAuthSecret<\/code>. N\u1ebfu b\u1ecb l\u1ed9, ch\u00fang c\u00f3 th\u1ec3 l\u00e0m suy y\u1ebfu c\u01a1 ch\u1ebf x\u00e1c th\u1ef1c tr\u00ean ph\u1ea1m vi to\u00e0n h\u1ec7 th\u1ed1ng.<\/p>\n<p>M\u1ed9t c\u00f4ng c\u1ee5 vi\u1ebft b\u1eb1ng Go c\u00f2n \u0111\u1ecdc <code>\/opt\/zimbra\/conf\/localconfig.xml<\/code>, t\u1ea1o chu\u1ed7i k\u1ebft n\u1ed1i MySQL v\u00e0 LDAP, r\u1ed3i xu\u1ea5t d\u1eef li\u1ec7u h\u1ed9p th\u01b0, si\u00eau d\u1eef li\u1ec7u, thi\u1ebft b\u1ecb di \u0111\u1ed9ng, thi\u1ebft l\u1eadp tr\u1ea3 l\u1eddi v\u1eafng m\u1eb7t c\u00f9ng c\u00e1c b\u1ea3ng trong kh\u00f4ng gian t\u00ean Zimbra.<\/p>\n<h2>Zimclient2 paves the way for sustainable access<\/h2>\n<p>In at least one campaign, a shell downloader installs Zimdown2, then deploys the remote access agent Zimclient2. This tool supports interactive shells, bidirectional file transfer, and SOCKS5 proxies over WebSocket, TLS, or raw TCP. Those capabilities allow maintaining access and turn the hijacked mail server into a springboard to the intranet.<\/p>\n<h2>Collect mailboxes and get the data out<\/h2>\n<p>C\u00e1c t\u1ec7p ch\u1ee9a th\u00f4ng tin x\u00e1c th\u1ef1c, ch\u1ee9ng th\u01b0, b\u00ed m\u1eadt LDAP, quy t\u1eafc th\u01b0 v\u00e0 c\u1ea5u h\u00ecnh \u0111\u01b0\u1ee3c gom l\u1ea1i th\u00e0nh kho ZIP. Tr\u00ean m\u1ed9t m\u00e1y ch\u1ee7, t\u00e1c nh\u00e2n c\u00f2n \u0111\u00f3ng g\u00f3i b\u1ea3n sao l\u01b0u h\u1ed9p th\u01b0 g\u1ea7n \u0111\u00e2y v\u00e0o <code>\/opt\/zimbra\/final.tar.gz<\/code>, t\u1ea3i AzCopy v\u00e0 th\u1eed chuy\u1ec3n d\u1eef li\u1ec7u t\u1edbi Azure Blob Storage. Microsoft ch\u01b0a c\u00f3 \u0111\u1ee7 b\u1eb1ng ch\u1ee9ng \u0111\u1ec3 kh\u1eb3ng \u0111\u1ecbnh l\u1ea7n truy\u1ec1n n\u00e0y ho\u00e0n t\u1ea5t.<\/p>\n<h2>Signs to investigate<\/h2>\n<p>Qu\u1ea3n tr\u1ecb vi\u00ean n\u00ean ki\u1ec3m tra <code>\/var\/log\/zimbra.log<\/code> \u0111\u1ec3 t\u00ecm l\u1ea7n kh\u1edfi \u0111\u1ed9ng l\u1ea1i d\u1ecbch v\u1ee5 b\u1ea5t th\u01b0\u1eddng; r\u00e0 so\u00e1t t\u1ec7p m\u1edbi trong th\u01b0 m\u1ee5c t\u1ea1m v\u00e0 c\u00e1c \u0111\u01b0\u1eddng d\u1eabn <code>webapps<\/code>; t\u00ecm web shell JSP, d\u1ecbch v\u1ee5 systemd l\u1ea1, cron, kh\u00f3a SSH m\u1edbi, t\u00e0i kho\u1ea3n c\u1ee5c b\u1ed9 v\u00e0 ti\u1ebfn tr\u00ecnh ch\u1ec9 t\u1ed3n t\u1ea1i trong b\u1ed9 nh\u1edb. Vi\u1ec7c ch\u1ec9 c\u00e0i b\u1ea3n v\u00e1 kh\u00f4ng lo\u1ea1i b\u1ecf d\u1ea5u v\u1ebft x\u00e2m nh\u1eadp \u0111\u00e3 c\u00f3 tr\u01b0\u1edbc \u0111\u00f3.<\/p>\n<h2>Prioritize response<\/h2>\n<ol>\n<li>Upgrade now to Zimbra 10.1.20 or later.<\/li>\n<li>N\u1ebfu ch\u01b0a th\u1ec3 v\u00e1, g\u1ee1 <code>zimbra-snmp<\/code>, t\u1eaft th\u00f4ng b\u00e1o SNMP v\u00e0 gi\u1edbi h\u1ea1n SMTP\/SNMP \u1edf c\u00e1c ngu\u1ed3n tin c\u1eady.<\/li>\n<li>Isolate compromised servers, preserve evidence, and hunt cluster-wide web shells.<\/li>\n<li>Turn Zimbra authentication secrets, service keys, credentials, and credentials potentially exposed.<\/li>\n<li>Review horizontal movement, LDAP\/MySQL queries, traffic to cloud storage, and nodes that once trusted the affected server.<\/li>\n<\/ol>\n<h2>Defensive Lessons<\/h2>\n<p>The mail server not only contains the contents of the exchange, but also holds keys and trust relations with many other systems. So an error in the optional component can still result in an organisational impact. Inventory of installation packages, reduction of unnecessary services, patching according to actual exploitation risks, and preparation of a secret rotation process are important measures to narrow the consequences.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from Microsoft, Zimbra, CERT Polska, CISA, and The Hacker News<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>CVE-2026-73570 cho th\u1ea5y m\u1ed9t email \u0111\u01b0\u1ee3c t\u1ea1o \u0111\u1eb7c bi\u1ec7t c\u00f3 th\u1ec3 tr\u1edf th\u00e0nh \u0111i\u1ec3m kh\u1edfi \u0111\u1ea7u c\u1ee7a chu\u1ed7i x\u00e2m nh\u1eadp nghi\u00eam tr\u1ecdng: th\u1ef1c thi l\u1ec7nh t\u1eeb xa, c\u00e0i web shell, \u0111\u00e1nh c\u1eafp b\u00ed m\u1eadt x\u00e1c th\u1ef1c, \u0111\u1ecdc d\u1eef li\u1ec7u h\u1ed9p th\u01b0 v\u00e0 di chuy\u1ec3n ngang gi\u1eefa c\u00e1c m\u00e1y ch\u1ee7 Zimbra. Microsoft ghi nh\u1eadn ho\u1ea1t \u0111\u1ed9ng [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":2071,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[70],"tags":[784,167,894,781,897,277,895,896],"class_list":["post-2072","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ho-so","tag-bao-mat-email","tag-cisa-kev","tag-cve-2026-73570","tag-microsoft-security-research","tag-snmp","tag-web-shell","tag-zimbra","tag-zimbra-collaboration-suite"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2072","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=2072"}],"version-history":[{"count":0,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2072\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/2071"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=2072"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=2072"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=2072"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}