Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Summary
Threat actors associated with the Cl0p ransomware group are actively exploiting unauthenticated Remote Code Execution (RCE) vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. This new data extortion campaign involves chaining an information disclosure flaw in FlexPLM with a server-side vulnerability in Windchill's login functionality.
IFF Assessment
This article details a new exploitation campaign by a known ransomware group targeting specific software, posing a direct threat to organizations using these products.
Severity
The exploitation allows for unauthenticated remote code execution and data extortion, indicating a high impact and exploitability. The chaining of vulnerabilities suggests a complex but achievable attack vector, leading to a critical severity score.
Defender Context
Organizations using PTC Windchill or FlexPLM should prioritize patching and securing these internet-exposed instances. Defenders need to be aware of this active exploitation campaign by Cl0p affiliates and monitor for indicators of compromise related to these specific vulnerabilities and software.