Executive brief
AD-Security AD_Miner is an audit tool used to identify security weaknesses in Active Directory environments. A vulnerability in its cache handling component allows a local attacker to execute malicious code on a user's system. This occurs when the tool is used to analyze a specially crafted cache file, potentially leading to a full system compromise if an analyst is tricked into loading a malicious file from an untrusted source.
Technical details
A deserialization vulnerability exists in AD-Security AD_Miner 1.9.0 within the `request_a` function of `ad_miner/scripts/analyse_cache.py`. The application uses the Python `pickle` module to load cache files specified via the first command-line argument (`sys.argv[1]`) without proper validation. Because `pickle.load()` can be subverted to execute arbitrary Python code during the reconstruction of objects, a local attacker can provide a malicious `.pkl` file to achieve arbitrary code execution in the context of the user running the script. While the attack requires local access or social engineering to persuade a user to load a malicious file, it poses a risk in collaborative environments where cache files are shared. A pull request (#239) has been submitted to implement a restricted unpickler to mitigate this issue.
Affected products
- AD-Security AD_Miner 1.9.0
Timeline
- 2026-06-04: disclosed: Issue and pull request opened on GitHub
- 2026-07-05: advisory: CVE published in NVD dataset