Local Privilege Escalation Vulnerability in Redundancy Module Configuration Tool by Rockwell Automation
CVE-2026-9634

7HIGH

What is CVE-2026-9634?

A local privilege escalation vulnerability exists in Rockwell Automation's Redundancy Module Configuration Tool, specifically within the RMConfigTool.exe binary. The tool improperly searches directories in the system path for a required dynamic link library (DLL). Due to incorrect default permissions, one or more of these directories may be writable by standard (non-administrator) users. If an attacker with local access places a malicious DLL in such a directory, and an administrator runs the tool, this malicious DLL is executed in the context of the elevated process, granting the attacker Administrator/SYSTEM privileges. Users are advised to review security advisories and apply necessary updates to mitigate this vulnerability.

Affected Version(s)

Redundancy Module Configuration Tool 10.00.00

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.