Technology newsroom
Urgent alert! A PTC Windchill vulnerability is being exploited by ransomware. It is recommended to update the patch immediately π¨
Urgent Alert! A severe vulnerability attack has been found on PTC Windchill by the ransomware group Hunters International, which allows hackers to run remote code without authentication. Users are advised to update the patch immediately.
π Summary of important points:
- A critical vulnerability of the Unsafe Deserialization type allows attackers to execute remote code (RCE) without authentication
- The ransomware group Hunters International is exploiting this vulnerability to infiltrate systems and encrypt files for ransom
- CISA has added this vulnerability to the list of highest priority watch items and recommends that organizations using PTC Windchill urgently update the security patch.
There is an urgent report from SecurityWeek and the Cybersecurity and Infrastructure Security Agency (CISA) warning about ongoing attacks exploiting a critical security vulnerability in PTC Windchill software, which is a Product Lifecycle Management (PLM) platform widely used in the manufacturing and engineering sectors.
π₯ Vulnerabilities and Attacks
The vulnerability is of the Unsafe Deserialization type with a Critical severity level, which allows malicious actors to successfully execute harmful code remotely on servers with Windchill installed without needing to go through any authentication process, making it an extremely easy target for attacks. A ransomware group called Hunters International has exploited this vulnerability to infiltrate targeted organizations.
π Attack tactics and impacts
After the attackers were able to access the system initially through a vulnerability, they used tools such as Cobalt Strike and AnyDesk to move laterally within the network and create a long-term access channel (Persistence). Then they installed Ransomware to encrypt all important files in the system, and the encrypted files were renamed with the .HUNTERS extension, which is the symbol of the attacker group, before leaving a ransom note.
π‘οΈ Advice and Protection
PTC has released a patch to fix this vulnerability since July 2023, but many organizations have not yet updated, leaving a high risk. CISA has added this vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog, which serves as a reminder for government and private sector agencies to urgently apply the security patch to prevent potential damage from this ransomware attack.
π¬ Does your organization regularly check and update the software patches in use? Let's share security management approaches.