Rockwell Automation Redundancy Module Configuration Tool
CISA warns CVE-2026-9633 in Rockwell Automation Redundancy Module Configuration Tool lets attackers execute processes with administrator privileges; fix in 10.01.00.
CISA released an ICS advisory for Rockwell Automation Redundancy Module Configuration Tool. CVE-2026-9633 could allow an attacker to escalate privileges and execute processes with administrator rights. Versions 9.00.00 through 10.00.00 are affected, and the vendor shipped a fix in version 10.01.00.
- CVE-2026-9633 allows admin-level process execution
- Versions 9.00.00 through 10.00.00 affected
- Vendor fix available in version 10.01.00
- Mitigation guidance provided for users who cannot upgrade
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-9633 | DLL Hijacking LPE in Rockwell Automation Redundancy Module Configuration Tool Rockwell Automation's Redundancy Module Configuration Tool (RM3ConfigTool.exe) is vulnerable to a DLL search-order hijacking issue caused by incorrect default directory permissions (CWE-276). The binary searches directories listed in the system PATH for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users; a local attacker can plant a malicious DLL there, and when an administrator subsequently launches the tool, the malicious DLL is loaded and executes with Administrator or SYSTEM privileges. Exploitation requires low local privileges plus user interaction (an administrator running the tool), and yields full privilege escalation on the affected workstation. Any installation of the Redundancy Module Configuration Tool on Windows where writable PATH directories exist is affected; the available data does not specify affected version ranges. There is no known public proof-of-concept, no entry in the CISA KEV catalog, and EPSS estimates only about a 0.1% probability of exploitation within 30 days. Do: Upgrade the Redundancy Module Configuration Tool to a patched version when Rockwell Automation publishes one, as no fixed version is identified in the available data. As an interim mitigation, review permissions on directories in the system PATH on Windows hosts running the tool and remove write access for standard (non-administrator) users, and check those directories for unexpected or recently added DLLs. Restrict execution of RM3ConfigTool.exe to administrator accounts until a fix is applied. | 7.0 | <1% |
| niche |
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool >=9.00.00| =9.00.00|<=10.00.00 Product Status: known_affected Remediations Vendor fix Rockwell Automation has released Redundancy Module Configuration Tool version 10.01.00 for users to install. Mitigation Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's…
This source does not provide full text. Read it at cisa.gov.