As cited
Copy frozen at (site build).
vulnerabilities
Rockwell Automation Redundancy Module Configuration Tool
Rockwell Automation disclosed two high-severity privilege escalation vulnerabilities (CVE-2026-9633 and CVE-2026-9634) in the Redundancy Module Configuration Tool caused by incorrect default permissions that allow standard users to write to directories searched by the application for DLL files. An attacker with local access could place a malicious DLL in a writable directory, which executes with administrator privileges when an authorized user runs the tool. Version 10.01.00 is available to remediate both vulnerabilities.
Why it matters: Organizations deploying Rockwell Automation's Redundancy Module Configuration Tool in critical manufacturing environments must upgrade to version 10.01.00 immediately, as local attackers can escalate to system-level privileges if unpatched systems are present on networks with untrusted users.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Rockwell Automation Redundancy Module Configuration Tool
Rockwell Automation disclosed two high-severity privilege escalation vulnerabilities (CVE-2026-9633 and CVE-2026-9634) in the Redundancy Module Configuration Tool caused by incorrect default permissions that allow standard users to write to directories searched by the application for DLL files. An attacker with local access could place a malicious DLL in a writable directory, which executes with administrator privileges when an authorized user runs the tool. Version 10.01.00 is available to remediate both vulnerabilities.
Why it matters: Organizations deploying Rockwell Automation's Redundancy Module Configuration Tool in critical manufacturing environments must upgrade to version 10.01.00 immediately, as local attackers can escalate to system-level privileges if unpatched systems are present on networks with untrusted users.
- Source published
- First seen by Cybersecurity Tracker