Executive brief
The Redundancy Module Configuration Tool from Rockwell Automation is used to configure and manage industrial redundancy hardware in critical manufacturing environments. A local attacker can exploit incorrect file permissions to place a malicious DLL file in a system directory, and when an administrator runs the tool, the attacker's code executes with full system privileges, potentially compromising the entire industrial control system.
Technical details
This vulnerability involves a classic DLL search order hijacking attack arising from incorrect default file permissions. The RMConfigTool.exe and RM3ConfigTool.exe binaries dynamically load DLLs using system PATH directories, some of which are writable by non-administrator users due to CWE-276 (Incorrect Default Permissions). A local attacker with standard user privileges can place a malicious DLL in a writable PATH directory; when an administrator subsequently executes the configuration tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges, enabling arbitrary code execution in the context of the industrial control system. The vulnerability requires local access and user interaction (administrator executing the tool), but no authentication is required from the attacker. Rockwell Automation has released version 10.01.00 containing corrected file permissions; no workaround is available for affected older versions.
Affected products
- Rockwell Automation Redundancy Module Configuration Tool 9.00.00 through 10.00.00 (CVE-2026-9634); 10.00.00 (CVE-2026-9633); fixed in 10.01.00
Timeline
- 2026-09-01: disclosed: CVE-2026-9634 published; advisory SD1800 released
- 2026-09-01: patched: Fix available in version 10.01.00