Security1 distinct publisher2 min readPublished
CVE-2026-9633 and CVE-2026-9634 let a standard user on a Windows host plant a DLL where the tool will look for it, then collect Administrator or SYSTEM the next time an admin runs it. Version 10.01.00 fixes both.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The trigger decides how hard this is to pull off. There is no race and no crafted input. A standard user drops a DLL into a directory that already sits on the system path and waits for an administrator to open the tool, at which point the DLL is loaded into the elevated process and runs with Administrator or SYSTEM rights [4]. Rockwell reported both issues to CISA itself [8], and both are filed under CWE-276, incorrect default permissions, with no list of the offending directories in the advisory [5].
The version arithmetic matters for what gets fixed. CVE-2026-9633 names RM3ConfigTool.exe in 10.00.00 [2]. CVE-2026-9634 names RMConfigTool.exe across 9.00.00 to 10.00.00 inclusive [3]. The overlap on 10.00.00 means an install at that build is reachable through both binaries, while a 9.x install appears only in the wider entry [11]. The remediation is the same package either way: 10.01.00, one minor revision above the highest affected build [6][14].
Then there is the mitigation section. CISA's recommended practices here are the standard control-system set, which is to keep devices off the internet, put control networks behind firewalls isolated from business networks, and use VPNs where remote access is required [10]. None of it bears on this bug. The precondition is a local account on the host where the tool is installed plus an administrator who later launches it [12]. Segmentation that stops CIP traffic does not stop a file write into a directory the operating system already searches.
That leaves two jobs, both host-local. One is installing 10.01.00, or, for sites that cannot, Rockwell's best-practices guidance [6][7]. The other is enumerating the system path on the workstations that actually have the tool and testing each entry for standard-user write access, because the advisory does not say which entry is wrong [5]. Scope is an inventory question rather than a network one. The tool is deployed worldwide into Critical Manufacturing [9], and the exposed population on any given host is whoever can log in without admin rights. As published, the advisory carries no CVSS score in its metrics sections [13]; the mechanism is legible enough that a number would not change the work.
Ranked by verification strength, evidence, and original report placement.
CISA published ICS advisory ICSA-26-244-02 on Rockwell Automation's Redundancy Module Configuration Tool, covering two vulnerabilities whose successful exploitation could allow an attacker to escalate and execute processes with administrator privileges.
CVE-2026-9633 affects Redundancy Module Configuration Tool version 10.00.00, in the binary RM3ConfigTool.exe.
CVE-2026-9634 affects Redundancy Module Configuration Tool versions >=9.00.00 through <=10.00.00, in the binary RMConfigTool.exe.
The affected binary searches directories in the system path for a required DLL, and one or more of those directories may be writable by standard, non-administrator users due to incorrect default permissions; if a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.
Both entries are classified as CWE-276 Incorrect Default Permissions, and the advisory does not identify which system path directories carry the permissive default permissions.
Rockwell Automation has released Redundancy Module Configuration Tool version 10.01.00 for users to install.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
One malformed CIP message faults a Logix controller until someone power-cycles it1 distinct publisher
security
CISA's Ebyte advisory carries no fixed version, because the vendor stopped answering1 distinct publisher
security
Johnson Controls console holds passwords in cleartext memory, and the fix line names two versions1 distinct publisher
security
A low-privilege login reaches code execution on Rockwell's FactoryTalk Historian ME1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary account, blank severity
This is about as close to a primary document as vulnerability reporting gets: CISA names both binaries, both CVEs, exact version boundaries and the weakness class. What it withholds is as telling as what it states — the Metrics fields are empty, so there is no score or vector to argue with, and the text says only that 'one or more' system path directories may be writable without naming a single one. Precise where a defender needs precision, unverifiable everywhere else.
No uptake signal
Rockwell shipped 10.01.00 and CISA calls deployment worldwide, but nothing here counts installations, tracks how many have moved to the fixed build, or reports an attempt at the technique — CISA says only that it has heard of no public exploitation. There is no quantity in this reporting to measure, and inventing one would be worse than leaving it blank.
Undersold by its own guidance
Nobody is overselling this one. If anything the advisory sells it short: the defenses recommended are the standard control-system trio — off the internet, behind a firewall, VPN for remote access — and not one of them touches an attack that starts with an ordinary user writing a file on the same Windows host. Read literally, the guidance points away from the vector, and with the severity fields empty there is no number pulling attention back.
Vendor found it, vendor fixes it
The flaw, the description, the framing and the only remedy all originate with Rockwell, which reported it to CISA and shipped 10.01.00; CISA relays the package without adding an independent severity judgment. That is ordinary practice in industrial disclosure, not misconduct — but the party with the most to lose from an alarming score is also the party that supplied the words and left the score field empty.
Mechanics firm, magnitude open
A defender can act on this today: the versions are stated, the binaries are named, the fixed build is identified. What stays out of reach is how much it matters — no severity metric, no install base, no second account, and no list of the directories to inspect. Our confidence tracks the actionable part and stops where the advisory does.