{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/redundancy-module-configuration-tool-9.00.00-and-10.00.00/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rockwellautomation:redundancy_module_configuration_tool:9.00.00:*:*:*:*:*:*:*","cpe:2.3:a:rockwellautomation:redundancy_module_configuration_tool:10.00.00:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-9633"},{"id":"CVE-2026-9634"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Redundancy Module Configuration Tool (10.00.00)","Redundancy Module Configuration Tool (\u003e=9.00.00 and \u003c=10.00.00)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","dll-hijacking","industrial-control-systems","windows"],"_cs_type":"advisory","_cs_vendors":["Rockwell Automation"],"content_html":"\u003cp\u003eRockwell Automation has disclosed two local privilege escalation vulnerabilities (CVE-2026-9633 and CVE-2026-9634) affecting the Redundancy Module Configuration Tool. The vulnerabilities arise from insecure directory permissions in the system path. Because the RM3ConfigTool.exe and RMConfigTool.exe binaries perform insecure library loading by searching for required DLLs in locations writable by standard users, a local attacker can plant a malicious DLL. When an administrator subsequently executes the tool, the malicious library is loaded into the elevated process context, resulting in code execution with Administrator or SYSTEM privileges. These vulnerabilities are limited to local exploitation and require a user with standard privileges to perform the initial file placement. Users are advised to upgrade to version 10.01.00 immediately.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains local access to the Windows workstation where the Redundancy Module Configuration Tool is installed.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a directory in the system PATH that is writable by non-administrator users.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious DLL that mimics the name of a library required by the target application (RM3ConfigTool.exe or RMConfigTool.exe).\u003c/li\u003e\n\u003cli\u003eAttacker writes the malicious DLL to the identified writable directory.\u003c/li\u003e\n\u003cli\u003eAn administrator account logs onto the system or initiates the configuration tool.\u003c/li\u003e\n\u003cli\u003eThe target application performs a DLL search and loads the malicious library from the attacker-controlled location.\u003c/li\u003e\n\u003cli\u003eMalicious code executes within the context of the elevated process (SYSTEM or Administrator).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local, non-privileged attacker to escalate privileges to Administrator or SYSTEM level on the host system. This could lead to full system compromise, exfiltration of sensitive configuration data, or manipulation of industrial control processes if the workstation has direct access to operational technology (OT) networks. These vulnerabilities affect critical manufacturing environments globally.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to Redundancy Module Configuration Tool version 10.01.00 immediately to remediate CVE-2026-9633 and CVE-2026-9634.\u003c/li\u003e\n\u003cli\u003eImplement strict access control lists (ACLs) on system directories to ensure standard users cannot write files to locations that influence application search paths.\u003c/li\u003e\n\u003cli\u003eDeploy Sysmon to monitor for unexpected DLL loads from non-standard or user-writable directories.\u003c/li\u003e\n\u003cli\u003eReview security guidance provided by Rockwell Automation in the Trust Center.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T17:11:12Z","date_published":"2026-09-01T17:11:12Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rockwell-redundancy-tool-vulnerabilities/","summary":"Rockwell Automation Redundancy Module Configuration Tool versions 9.x and 10.00.00 are vulnerable to DLL hijacking, potentially allowing local privilege escalation to SYSTEM level.","title":"DLL Hijacking Vulnerabilities in Rockwell Automation Redundancy Module Configuration Tool","url":"https://feed.craftedsignal.io/briefs/2026-09-rockwell-redundancy-tool-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Redundancy Module Configuration Tool (\u003e=9.00.00 and \u003c=10.00.00)","version":"https://jsonfeed.org/version/1.1"}