Security Flaw in Redundancy Module Configuration Tool by Rockwell Automation
CVE-2026-9633

7HIGH

What is CVE-2026-9633?

A security issue has been identified in the Redundancy Module Configuration Tool where the RM3ConfigTool.exe binary improperly handles DLL searches. It searches directories within the system path, some of which may permit write access to standard users due to incorrect default permissions. Malicious actors can exploit this flaw by placing a rogue DLL within these directories. When an administrator runs the tool, the malicious DLL is executed with elevated privileges, compromising the system's security.

Affected Version(s)

Redundancy Module Configuration Tool 10.00.00

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.