CVE-2026-9634
nicheLocal privilege escalation via DLL hijacking in Rockwell Redundancy Module Config Tool
Rockwell Automation's Redundancy Module Configuration Tool (RMConfigTool.exe) locates a required DLL by searching directories in the system PATH, and due to incorrect default permissions (CWE-276) one or more of those directories may be writable by standard, non-administrator users. A local attacker with low-privileged access to the machine can plant a malicious DLL in such a directory, and when an administrator subsequently launches the tool, the DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges. The result is local privilege escalation giving the attacker high-impact control over the confidentiality, integrity, and availability of the host, though the attack requires an administrator to run the tool (user interaction is part of the exploit conditions). Affected users are organizations running the Redundancy Module Configuration Tool on Windows engineering or administrator workstations; specific affected version ranges were not provided in the available data. No public proof-of-concept, CISA KEV listing, or known exploitation exists, and EPSS currently estimates only a 0.1% probability of exploitation in the next 30 days.
What to do: Until Rockwell publishes a fix, check the access-control lists on directories in the system PATH and restrict write access to administrators only, and avoid launching RMConfigTool.exe while untrusted local users can write to those directories. Monitor Rockwell Automation's security advisory (CNA: [email protected]) for the definitive affected-version list and an updated release, and upgrade when available. Prioritize remediation on shared, multi-user engineering workstations where the tool is installed, since exploitation requires an existing local low-privileged foothold.
| Rockwell Automation Redundancy Module Configuration Tool (RMConfigTool.exe) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.
- Weakness
- CWE-276
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.