Rockwell Automation Redundancy Module Configuration Tool
September 1, 2026 · CISA (US-CERT) · Severity: CRITICAL
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 (CVE-2026-9634) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation Redundancy Module Configuration Tool Incorrect Default Permissions Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9633 A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges. View CVE Details Affected Products Rockwell Automation Redundancy Module Configuration Tool Vendor:Rockwell Automation Product Version:Rockwell Automation Redundancy Module Configuration Tool: 10.00.00 Product Status:known_affected Remediations Vendor fixRockwell Automation has released Redundancy Module Configuration Tool version 10.01.00 for users to install. MitigationCustomers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices...
Key Takeaways
- CISA published an advisory for the Rockwell Automation Redundancy Module Configuration Tool covering a privilege escalation vulnerability.
- Successful exploitation of the flaw could allow an attacker to escalate privileges and execute processes with administrator privileges on affected systems.
- CISA's advisory covers version 10.00 of the Redundancy Module Configuration Tool, and organizations should apply vendor updates and restrict tool access.