🔴 Critical  |  Source: The Hacker News


Affiliates of the Cl0p ransomware group are actively exploiting vulnerabilities in PTC Windchill and FlexPLM, two widely used product lifecycle management platforms. Attackers chain a pre-authentication information disclosure flaw in FlexPLM’s WSDL endpoint with a server-side vulnerability in the Windchill login servlet to achieve unauthenticated remote code execution. Any organisation with internet-exposed instances of these products is at immediate risk of data theft and extortion.

Security Architect’s Take: Immediately audit your environment for internet-exposed PTC Windchill or FlexPLM instances and take them off the public internet or place them behind a VPN or zero-trust access gateway. Apply all available vendor patches without delay and review ingress firewall rules and WAF policies to block exploitation attempts at the perimeter while patching is in progress.

Original advisory: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE