Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Summary

Threat actors associated with the Cl0p ransomware group are actively exploiting unauthenticated Remote Code Execution (RCE) vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. This new data extortion campaign involves chaining an information disclosure flaw in FlexPLM with a server-side vulnerability in Windchill's login functionality.

IFF Assessment

FOE

This article details a new exploitation campaign by a known ransomware group targeting specific software, posing a direct threat to organizations using these products.

Severity

9.8 Critical (AI Estimated)

The exploitation allows for unauthenticated remote code execution and data extortion, indicating a high impact and exploitability. The chaining of vulnerabilities suggests a complex but achievable attack vector, leading to a critical severity score.

Defender Context

Organizations using PTC Windchill or FlexPLM should prioritize patching and securing these internet-exposed instances. Defenders need to be aware of this active exploitation campaign by Cl0p affiliates and monitor for indicators of compromise related to these specific vulnerabilities and software.

Read Full Story →