CISA disclosed two CWE-276 flaws in Rockwell Automation Redundancy Module Configuration Tool. A local low-privileged attacker can plant a malicious DLL to gain Administrator/SYSTEM execution when an a
CISA disclosed two CWE-276 flaws in Rockwell Automation Redundancy Module Configuration Tool. A local low-privileged attacker can plant a malicious DLL to gain Administrator/SYSTEM execution when an administrator runs the tool, a notable risk for critical manufacturing deployments despite no remote vector. # RockwellAutomation # PrivilegeEscalation # IcsSecurity https:// cyberworldops.eu/en/rockwe