Impact
A remote code execution flaw exists in PTC's Windchill PDMLink and FlexPLM products. The weakness arises from the improper handling of serialized objects from untrusted sources, allowing an attacker to deliver a crafted payload that triggers arbitrary code execution inside the application process. If successfully exploited, the attacker can gain the privileges of the application, potentially compromising the entire server or network.
Affected Systems
The vulnerable components are PTC FlexPLM and PTC Windchill PDMLink according to the CNA. No specific affected version numbers or build identifiers are listed in the advisory, so the impact could apply to any installations of these products that include the affected deserialization logic.
Risk and Exploitability
The CVSS score of 9.2 indicates a high severity and the exploitation likely occurs over a remote channel that transmits serialized data, such as network endpoints or file uploads. The EPSS score is not available, but the vulnerability is not currently listed in CISA's KEV catalog, suggesting no known widespread exploitation yet. Nonetheless, because the attack requires only the ability to send a malicious payload to the vulnerable endpoint, the probability of exploitation in exposed environments is significant.
OpenCVE Enrichment