CVE-2026-9633

A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.

Scoring

Severity
HIGH
CVSS base score
7
CVSS vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS probability
0.09%
CWE
CWE-276
Published
2026-09-01
Last modified
2026-09-01

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs