VYPR
advisoryPublished Sep 1, 2026· 1 source

Rockwell Automation Redundancy Module Configuration Tool Vulnerable to Privilege Escalation

CISA alerts users to two vulnerabilities in Rockwell Automation's Redundancy Module Configuration Tool that could allow local attackers to escalate privileges.

CISA has issued an advisory detailing two critical vulnerabilities, CVE-2026-9633 and CVE-2026-9634, affecting Rockwell Automation's Redundancy Module Configuration Tool. These flaws, identified within the RMConfigTool.exe binary, stem from incorrect default permissions that allow local attackers to place malicious DLL files into writable system path directories.

When an administrator subsequently runs the affected tool, these malicious DLLs can be loaded and executed with elevated privileges, potentially granting the attacker SYSTEM-level access. This privilege escalation could lead to a full compromise of the affected system, impacting critical infrastructure sectors, particularly in manufacturing, deployed worldwide.

CVE-2026-9633 specifically affects Redundancy Module Configuration Tool version 10.00.00. The vulnerability arises because the tool's executable searches system path directories for a required DLL, and some of these directories may be writable by standard users due to improper default permissions. A local attacker can exploit this by placing a malicious DLL in such a directory.

Similarly, CVE-2026-9634 impacts versions of the Redundancy Module Configuration Tool ranging from 9.00.00 up to and including 10.00.00. The mechanism of exploitation is identical to CVE-2026-9633, leveraging the tool's DLL search path and incorrect default permissions to achieve arbitrary code execution with elevated privileges.

Rockwell Automation has addressed these vulnerabilities by releasing version 10.01.00 of the Redundancy Module Configuration Tool. Users are strongly advised to upgrade to this patched version to mitigate the risks associated with these flaws. The company has also provided links to its security advisories for further information.

For organizations unable to immediately upgrade, Rockwell Automation recommends implementing its security best practices. CISA further advises minimizing network exposure for all control system devices, isolating them behind firewalls, and using secure remote access methods like VPNs, ensuring all components are kept up-to-date.

The vulnerabilities carry a CVSS v3.1 base score of 7.3 (High), with a CVSS 4.0 score of 7.0 (High). The attack vector is local, requiring low privileges and user interaction, but offering high impact on confidentiality, integrity, and availability.

These findings underscore the persistent threat of privilege escalation vulnerabilities in industrial control system (ICS) software, where improper permission configurations can have severe consequences for operational security and system integrity.

Synthesized by Vypr AI