CVE-2023-29444: PTC Kepware Kepserverex
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
An uncontrolled search path element vulnerability (DLL hijacking) has been discovered that could allow a locally authenticated adversary to escalate privileges to SYSTEM. Alternatively, they could host a trojanized version of the software and trick victims into downloading and installing their malicious version to gain initial access and code execution.
Affected products
- PTC Kepware Kepserverex: from 6.0.2107.0, up to and including 6.14.263.0
- PTC Thingworx Industrial Connectivity: from 8.0, up to and including 8.5
- PTC Thingworx Kepware Server: from 6.8, up to and including 6.14.263.0
Published 2024-01-10. Last modified 2026-06-17.