Executive brief
PTC Windchill is a product data management system used by manufacturers to manage engineering designs and product configurations. A remote code execution vulnerability through unsafe deserialization could allow attackers to execute arbitrary code on affected systems, potentially compromising sensitive product designs, supply chain data, and manufacturing operations.
Technical details
The vulnerability is a deserialization flaw that allows remote code execution. Untrusted data is deserialized without proper validation, enabling an attacker to craft malicious serialized objects that execute arbitrary code upon deserialization. The attack likely requires network access to the affected service. An attacker can achieve remote code execution on systems running vulnerable versions of PTC Windchill. Patch availability has not been confirmed from accessible sources.
Affected products
- PTC Windchill
- PTC FlexPLM
Timeline
- 2026-08-20: disclosed