SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-9633

HIGH · CVSS 7 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Redundancy Module Configuration Tool is vulnerable due to its reliance on system path directories that may be writable by non-administrator users, allowing local attackers to place a malicious DLL. If an administrator runs the tool, the malicious DLL can be executed with elevated privileges, potentially compromising the system. Organizations using this tool should prioritize remediation to mitigate the risk of local privilege escalation attacks.

CVE
CVE-2026-9633
Severity
HIGH
CVSS
7
EPSS
0.09%

Original NVD Description

A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.