CISA disclosed two CWE-276 flaws in Rockwell Automation Redundancy Module Configuration Tool. A local low-privileged attacker can plant a malicious DLL to gain Administrator/SYSTEM execution when an a

CISA disclosed two CWE-276 flaws in Rockwell Automation Redundancy Module Configuration Tool. A local low-privileged attacker can plant a malicious DLL to gain Administrator/SYSTEM execution when an administrator runs the tool, a notable risk for critical manufacturing deployments despite no remote vector. # RockwellAutomation # PrivilegeEscalation # IcsSecurity https:// cyberworldops.eu/en/rockwe

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CISA disclosed two CWE-276 flaws in Rockwell Automation Redundancy Module Configuration Tool. A local low-privileged attacker can plant a malicious DLL to gain Administrator/SYSTEM execution when an a

mastodon:infosec-exchangeother28d ago kagi ↗

CISA disclosed two CWE-276 flaws in Rockwell Automation Redundancy Module Configuration Tool. A local low-privileged attacker can plant a malicious DLL to gain Administrator/SYSTEM execution when an administrator runs the tool, a notable risk for critical manufacturing deployments despite no remote vector. # RockwellAutomation # PrivilegeEscalation # IcsSecurity https:// cyberworldops.eu/en/rockwe