Junglewise Threat Intelligence

CVE-2026-9633: Rockwell Automation Redundancy Module Configuration Tool DLL hijacking

CVE-2026-9633 · Severity: info · CVSS 7.3 · Published 2026-09-01

Vendors: Rockwell Automation.

Executive brief

Rockwell Automation's Redundancy Module Configuration Tool is used to manage redundancy systems in industrial control networks. The tool searches for required DLL files in system directories that may be writable by regular users. An attacker can place a malicious DLL in one of these directories, which will be loaded with Administrator/SYSTEM privileges when an administrator runs the tool, leading to complete system compromise.

Technical details

The vulnerability is a classic DLL hijacking / incorrect default permissions flaw (CWE-276). The RM3ConfigTool.exe binary searches system PATH directories for required DLLs, but one or more of these directories have overly permissive permissions allowing standard users to write files. An attacker with local access can place a malicious DLL in a writable PATH directory. When an administrator executes the tool, the malicious DLL is loaded into the process running with elevated privileges, achieving arbitrary code execution as Administrator or SYSTEM. Patch is available: upgrade to version 10.01.00 or later.

Affected products

  • Rockwell Automation Redundancy Module Configuration Tool 10.00.00 (corrected in 10.01.00)

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Version 10.01.00 released

References

Related threats