Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

DLL Hijacking Vulnerabilities in Rockwell Automation Redundancy Module Configuration Tool

Source context: this article examines information published by the source on September 01, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.

What the vulnerability is

Two vulnerabilities, identified as CVE-2026-9633 and CVE-2026-9634, exist in the Rockwell Automation Redundancy Module Configuration Tool. Both issues stem from incorrect default permissions (CWE-276) within system path directories.

The binaries RM3ConfigTool.exe (associated with CVE-2026-9633) and RMConfigTool.exe (associated with CVE-2026-9634) search the system path for required DLLs. Because some of these directories are writable by standard, non-administrator users, a local attacker could place a malicious DLL in one of these paths. If an account with administrator privileges subsequently executes the tool, the malicious DLL is loaded into the elevated process, allowing the attacker to execute code with Administrator or SYSTEM privileges.

Exposure and applicability

These vulnerabilities are not exploitable remotely; they require local access to the system where the software is installed. The affected versions differ slightly by CVE:

  • CVE-2026-9633: Affects version 10.00.00.
  • CVE-2026-9634: Affects versions >=9.00.00 and <=10.00.00.

Infrastructure owners should identify all workstations or servers running the Redundancy Module Configuration Tool within their critical manufacturing environments to determine if they are operating within these version ranges.

Remediation priorities

Our analysis suggests prioritizing remediation based on the level of local access granted to non-privileged users on systems hosting this tool.

Primary Corrective Action:
Update the Redundancy Module Configuration Tool to version 10.01.00. This is the vendor-supported fix to address the incorrect permissions leading to DLL hijacking.

Compensating Controls:
For environments where an immediate update is not feasible, we recommend implementing Rockwell Automation’s security best practices. While these do not resolve the root cause of the permission flaw, reducing the number of users with local access to the system can limit the pool of potential attackers capable of placing a malicious DLL.

How to validate remediation

To verify that exposure has been reduced, defenders should perform the following:

  1. Version Verification: Confirm that the installed version of the Redundancy Module Configuration Tool is 10.01.00 or later. Note that a version check confirms the update was applied but does not prove the absence of previously placed malicious files.
  2. Permission Audit: For systems that cannot be updated, verify the write permissions of directories in the system path used by RM3ConfigTool.exe and RMConfigTool.exe. Ensuring these directories are not writable by non-administrator users would mitigate the specific entry path described.

Limits and open questions

Updating to version 10.01.00 addresses the vulnerability in the software’s default configuration, but it does not automatically scan for or remove malicious DLLs that may have been placed in system paths prior to the update. Residual risk remains if the system was already compromised.

Additionally, while CISA reports no known public exploitation of these vulnerabilities, the effectiveness of compensating controls depends entirely on the existing local security posture and the ability to restrict non-administrative write access to critical system directories.

Source and editorial note

Rockwell Automation Redundancy Module Configuration Tool · Source date: September 01, 2026 · Retrieved September 01, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment