Executive Summary

In September 2026, CISA disclosed two critical privilege escalation vulnerabilities (CVE-2026-9633 and CVE-2026-9634) in Rockwell Automation's Redundancy Module Configuration Tool affecting versions 9.00.00 through 10.00.00. The vulnerabilities stem from incorrect default permissions that allow the tool's executables to search for required DLLs in directories writable by standard users. If exploited, local attackers can place malicious DLLs in these directories, which are then loaded with Administrator/SYSTEM privileges when the tool is run by an administrator. Rockwell Automation has released version 10.01.00 to address these issues, affecting critical manufacturing infrastructure worldwide.

This incident highlights the persistent threat of DLL hijacking attacks in industrial control systems, particularly as organizations modernize their operational technology environments. With increasing convergence of IT and OT networks, such privilege escalation vulnerabilities pose significant risks to critical infrastructure security and operational continuity.

Why This Matters Now

Industrial control system vulnerabilities are increasingly targeted as critical infrastructure becomes more digitized. DLL hijacking represents a growing attack vector that can compromise manufacturing systems and operational technology environments with severe business impact.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

These are privilege escalation vulnerabilities in Rockwell Automation's Redundancy Module Configuration Tool that allow DLL hijacking attacks to gain Administrator/SYSTEM privileges.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this DLL hijacking attack by limiting lateral movement paths and reducing the attacker's ability to access critical manufacturing systems across network segments.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud native security posture may have provided enhanced visibility into workload behavior and identity-based access controls that could limit the scope of initial access to manufacturing systems

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely limit the scope and reachability of elevated privileges by constraining SYSTEM-level access to only specifically authorized manufacturing resources rather than broad network access

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely constrain lateral movement by blocking unauthorized communication between industrial control systems and limiting reachability to only explicitly permitted manufacturing network segments

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Comprehensive visibility and control mechanisms would likely detect and constrain unauthorized command channels, limiting the attacker's ability to maintain persistent access to manufacturing control systems

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress controls would likely constrain data exfiltration by blocking unauthorized outbound transfers of manufacturing configurations and operational data, limiting the scope of sensitive information that could leave the industrial environment

Impact (Mitigations)

While some operational risk may remain to the initially compromised manufacturing system, the scope of potential disruption would likely be constrained to isolated network segments rather than cascading across the entire industrial environment

Impact at a Glance

Affected Business Functions

  • Industrial Control Systems
  • Manufacturing Operations
  • Process Automation
  • Safety Systems
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

No data exposure indicated as vulnerabilities require local access and administrator interaction for exploitation

Recommended Actions

  • Implement Zero Trust segmentation to isolate industrial control systems and limit lateral movement from compromised endpoints
  • Deploy east-west traffic security controls to monitor and restrict workload-to-workload communications within critical manufacturing networks
  • Enable multicloud visibility and control to detect anomalous interactions and suspicious automation targeting industrial systems
  • Enforce egress security policies to prevent unauthorized data exfiltration from industrial environments to external destinations
  • Utilize threat detection and anomaly response capabilities to baseline normal industrial system behavior and alert on privilege escalation attempts

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image