PT-2026-84235 · Unknown · Redundancy Module Configuration Tool
CVE-2026-9634
·
Published
2026-09-01
·
Updated
2026-09-01
CVSS v4.0
7.0
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Redundancy Module Configuration Tool (affected versions not specified)
Description
A security issue exists in the
RMConfigTool.exe binary. The tool searches directories in the system path for a required DLL, but some of these directories may have incorrect default permissions, allowing standard non-administrator users to write to them. A local attacker can exploit this by placing a malicious DLL in one of these writable directories. When an administrator runs the tool, the malicious DLL is loaded into the elevated process, granting the attacker Administrator or SYSTEM privileges.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redundancy Module Configuration Tool