Impact
The Redundancy Module Configuration Tool searches directories in the system path for a required DLL. One or more of these directories can be writable by standard users because of incorrect default permissions. A local attacker can place a malicious DLL in such a directory, and when an administrator runs the tool the DLL is loaded into the elevated process and executed with Administrator/SYSTEM privileges. This flaw allows a local attacker to gain full system control through malicious code execution in an elevated process.
Affected Systems
Rockwell Automation’s Redundancy Module Configuration Tool, version 10.00.00, is vulnerable. The flaw is present in the RM3ConfigTool.exe binary shipped with this version.
Risk and Exploitability
The CVSS score of 7 indicates a high severity vulnerability. With no EPSS score available and the vulnerability not listed in the CISA KEV catalog, the exact exploitation frequency is unclear, but the impact is severe if exploited. The attack vector is local, requiring the attacker to write to a writable directory on the system path. Once the attacker has placed the DLL, any administrative user who runs the tool will expose the system to arbitrary code execution with SYSTEM privileges.
OpenCVE Enrichment