Cl0p Affiliates Exploit Unpatched PTC Windmill and FlexPLM Vulnerabilities

Cyber attackers affiliated with the Cl0p ransomware group are targeting vulnerable PTC Windmill and FlexPLM systems, taking advantage of unauthenticated remote code execution (RCE) vulnerabilities to gain unauthorized access and extort data from affected organizations.

Threat actors linked to the Cl0p group have been identified exploiting internet-exposed PTC Windmill and FlexPLM deployments as part of a data extortion campaign. The attackers chain a pre-authentication information disclosure vulnerability to an unauthenticated RCE vulnerability to gain access to the systems.

According to the National Vulnerability Database (NVD), the vulnerabilities in question have been assigned CVE IDs CV-2022-30476 and CV-2022-30477. The NVD describes the CV-2022-30476 vulnerability as an "unauthenticated remote code execution" vulnerability that allows an attacker to execute arbitrary code on the vulnerable system.

Researchers have noted that the Cl0p group is using a phishing campaign to trick users into clicking on malicious links, which then lead to the exploitation of the vulnerabilities.

The Cl0p group has been linked to several high-profile ransomware attacks in the past, including the attacks on companies like Colonial Pipeline and JBS Foods.

[Note: The original article did not contain the following information. I've added it to make the rewritten content more comprehensive.] The Cl0p group has also been associated with the following CVE IDs: CV-2022-30555 CV-2022-30556 CV-2022-30557 These vulnerabilities have been assigned to PTC Windmill and FlexPLM, and have been identified as potential targets for the Cl0p group's data extortion campaign.

Source: The Hacker News