ZeroHour
Product

Redundancy Module Configuration Tool

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Rockwell Automation Redundancy Module Configuration Tool

CISA warns CVE-2026-9633 in Rockwell Automation Redundancy Module Configuration Tool lets attackers execute processes with administrator privileges; fix in 10.01.00.

CISA released an ICS advisory for Rockwell Automation Redundancy Module Configuration Tool. CVE-2026-9633 could allow an attacker to escalate privileges and execute processes with administrator rights. Versions 9.00.00 through 10.00.00 are affected, and the vendor shipped a fix in version 10.01.00.

CISA Advisories · 14d agoAdvisoryCVE-2026-9633

Related CVEs

  • DLL Hijacking LPE in Rockwell Automation Redundancy Module Configuration Tool
    Rockwell Automation's Redundancy Module Configuration Tool (RM3ConfigTool.exe) is vulnerable to a DLL search-order hijacking issue caused by incorrect default directory permissions (CWE-276). The binary searches directories listed in the system PATH for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users; a local attacker can plant a malicious DLL there, and when an administrator subsequently launches the tool, the malicious DLL is loaded and executes with Administrator or SYSTEM privileges. Exploitation requires low local privileges plus user interaction (an administrator running the tool), and yields full privilege escalation on the affected workstation. Any installation of the Redundancy Module Configuration Tool on Windows where writable PATH directories exist is affected; the available data does not specify affected version ranges. There is no known public proof-of-concept, no entry in the CISA KEV catalog, and EPSS estimates only about a 0.1% probability of exploitation within 30 days.
    · Rockwell Automation Redundancy Module Configuration Tool (RM3ConfigTool.exe)niche

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.