PT-2026-84235 · Unknown · Redundancy Module Configuration Tool

CVE-2026-9634

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v4.0

7.0

High

VectorAV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Redundancy Module Configuration Tool (affected versions not specified)
Description A security issue exists in the RMConfigTool.exe binary. The tool searches directories in the system path for a required DLL, but some of these directories may have incorrect default permissions, allowing standard non-administrator users to write to them. A local attacker can exploit this by placing a malicious DLL in one of these writable directories. When an administrator runs the tool, the malicious DLL is loaded into the elevated process, granting the attacker Administrator or SYSTEM privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9634

Affected Products

Redundancy Module Configuration Tool