Executive Summary
In September 2026, CISA disclosed two critical privilege escalation vulnerabilities (CVE-2026-9633 and CVE-2026-9634) in Rockwell Automation's Redundancy Module Configuration Tool affecting versions 9.00.00 through 10.00.00. The vulnerabilities stem from incorrect default permissions that allow the tool's executables to search for required DLLs in directories writable by standard users. If exploited, local attackers can place malicious DLLs in these directories, which are then loaded with Administrator/SYSTEM privileges when the tool is run by an administrator. Rockwell Automation has released version 10.01.00 to address these issues, affecting critical manufacturing infrastructure worldwide.
This incident highlights the persistent threat of DLL hijacking attacks in industrial control systems, particularly as organizations modernize their operational technology environments. With increasing convergence of IT and OT networks, such privilege escalation vulnerabilities pose significant risks to critical infrastructure security and operational continuity.
Why This Matters Now
Industrial control system vulnerabilities are increasingly targeted as critical infrastructure becomes more digitized. DLL hijacking represents a growing attack vector that can compromise manufacturing systems and operational technology environments with severe business impact.
Attack Path Analysis
Attack leveraged DLL search order hijacking vulnerabilities (CVE-2026-9633/CVE-2026-9634) in Rockwell Automation Redundancy Module Configuration Tool. Local attacker with standard user privileges placed malicious DLL in writable system path directory, then waited for administrator to execute the vulnerable tool, resulting in privilege escalation to SYSTEM level access with potential for lateral movement and data exfiltration.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attacker gained initial local access to system running Rockwell Automation Redundancy Module Configuration Tool through standard user account
Related CVEs
CVE-2026-9633
CVSS 7DLL search order hijacking vulnerability in Rockwell Automation Redundancy Module Configuration Tool RM3ConfigTool.exe allows local attackers to escalate privileges to Administrator/SYSTEM by placing malicious DLLs in writable directories.
Affected Products:
Rockwell Automation Redundancy Module Configuration Tool – 10.00.00
Exploit Status:
no public exploitCVE-2026-9634
CVSS 7DLL search order hijacking vulnerability in Rockwell Automation Redundancy Module Configuration Tool RMConfigTool.exe allows local attackers to escalate privileges to Administrator/SYSTEM by placing malicious DLLs in writable directories.
Affected Products:
Rockwell Automation Redundancy Module Configuration Tool – 9.00.00 through 10.00.00
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Hijack Execution Flow: DLL Search Order Hijacking
Hijack Execution Flow
Exploitation for Privilege Escalation
Create or Modify System Process: Windows Service
Process Injection
User Execution: Malicious File
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Least Privilege
Control ID: AC-6
CISA Zero Trust Maturity Model 2.0 – Software platforms and applications within the organization are inventoried
Control ID: ID.AM-2
NIS2 Directive – Cybersecurity risk management measures
Control ID: Article 21
DORA – Identification and classification of ICT assets
Control ID: Article 8
ISO 27001:2022 – Privileged access rights
Control ID: A.8.2
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02(b)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
Local privilege escalation vulnerabilities in Rockwell Automation redundancy tools directly threaten industrial control systems requiring immediate patching and access controls.
Automotive
Manufacturing automation systems using Rockwell redundancy modules face privilege escalation risks that could disrupt production lines and compromise operational technology security.
Oil/Energy/Solar/Greentech
Critical infrastructure control systems vulnerable to DLL hijacking attacks enabling administrator privilege escalation, potentially impacting power generation and distribution operations.
Defense/Space
Mission-critical manufacturing and control systems face high-severity local privilege escalation threats requiring immediate remediation to maintain operational security and compliance.
Sources
- Rockwell Automation Redundancy Module Configuration Toolhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-244-02Verified
- Rockwell Automation Security Advisorieshttps://www.rockwellautomation.com/en-us/trust-center/security-advisories.htmlVerified
- Rockwell Automation Security Best Practiceshttps://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_USVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this DLL hijacking attack by limiting lateral movement paths and reducing the attacker's ability to access critical manufacturing systems across network segments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native security posture may have provided enhanced visibility into workload behavior and identity-based access controls that could limit the scope of initial access to manufacturing systems
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely limit the scope and reachability of elevated privileges by constraining SYSTEM-level access to only specifically authorized manufacturing resources rather than broad network access
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement by blocking unauthorized communication between industrial control systems and limiting reachability to only explicitly permitted manufacturing network segments
Control: Multicloud Visibility & Control
Mitigation: Comprehensive visibility and control mechanisms would likely detect and constrain unauthorized command channels, limiting the attacker's ability to maintain persistent access to manufacturing control systems
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely constrain data exfiltration by blocking unauthorized outbound transfers of manufacturing configurations and operational data, limiting the scope of sensitive information that could leave the industrial environment
While some operational risk may remain to the initially compromised manufacturing system, the scope of potential disruption would likely be constrained to isolated network segments rather than cascading across the entire industrial environment
Impact at a Glance
Affected Business Functions
- Industrial Control Systems
- Manufacturing Operations
- Process Automation
- Safety Systems
Estimated downtime: N/A
Estimated loss: N/A
No data exposure indicated as vulnerabilities require local access and administrator interaction for exploitation
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to isolate industrial control systems and limit lateral movement from compromised endpoints
- • Deploy east-west traffic security controls to monitor and restrict workload-to-workload communications within critical manufacturing networks
- • Enable multicloud visibility and control to detect anomalous interactions and suspicious automation targeting industrial systems
- • Enforce egress security policies to prevent unauthorized data exfiltration from industrial environments to external destinations
- • Utilize threat detection and anomaly response capabilities to baseline normal industrial system behavior and alert on privilege escalation attempts



