CVE-2026-9634
Received Received - Intake

RMConfigTool.exe DLL Hijacking Vulnerability

Vulnerability report for CVE-2026-9634, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Rockwell Automation

Description

A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
rockwell_automation redunancy_module_configuration_tool *
rockwell_automation redundancy_module_configuration_tool *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-276 During installation, installed file permissions are set to allow anyone to modify those files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the RMConfigTool.exe binary which searches system directories for a required DLL. Due to incorrect default permissions, standard users can write to these directories. An attacker can place a malicious DLL in such a directory. When an administrator runs the tool, the malicious DLL loads and executes with elevated privileges.

Detection Guidance

Check for writable directories in the system PATH where RMConfigTool.exe may load DLLs. Inspect directories for unexpected DLL files. Monitor process execution logs for RMConfigTool.exe launches by non-admin users.

Impact Analysis

If you are an administrator using the RMConfigTool, an attacker could gain full control of your system by exploiting this flaw. Standard users could plant malware that executes with SYSTEM privileges when the tool is run.

Compliance Impact

This vulnerability could lead to unauthorized system access, potentially violating data protection requirements under GDPR or HIPAA. Unauthorized privilege escalation may result in data breaches or non-compliance with security control mandates.

Mitigation Strategies

Remove write permissions from directories in the system PATH. Ensure only trusted users can modify PATH directories. Replace RMConfigTool.exe with a version that uses absolute DLL paths or a secure directory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9634. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart