A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030
| Vendor | Product | Versions |
|---|---|---|
| ptc | flexplm | 0, 11.1 M020, 11.2.1.0, 12.0.2.0, 12.1.2.0, 13.0.2.0, 13.1.0.0, 13.1.1.0, 13.1.2.0, 13.1.3.0, 0, 11.1 M020, 11.2.1.0, 12.0.0.0, 12.0.2.0, 12.1.2.0, 12.1.3.0, 13.0.2.0, 13.0.3.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| ptc | ptc flexplm | cert_advisory | 90% |
| ptc | ptc windchill | cert_advisory | 90% |
| ptc | windchill_pdmlink | cve_cpe | 95% |
Updated product name to FlexPLM, added new tags related to known exploited vulnerabilities and JSP webshells.
Updated severity to CRITICAL, added CVSS score of 9.3, and included new indicators of compromise and a new patch version.
Updated description with new technical details, changed severity to CRITICAL, and updated CVSS score to 9.3, along with new IoCs.
Updated description with technical details, changed severity to HIGH, and added IoCs.
Updated description with technical details, added affected version 11.0 M030, changed severity to CRITICAL, updated CVSS score to 10.0, and provided patch release date of 15.06.2026.
Updated severity to CRITICAL, added new description with details on improper input validation, and noted that no exploit is available.
Initial creation