If you run Creo Elements/Direct License Server (MEls) version 20.7.0.0 or earlier, upgrade to 20.7.0.1 or later immediately. PTC rates CVE-2024-6071 at CVSS 3.1 10.0, and an unauthenticated remote attacker can use the product’s web interface to execute arbitrary operating-system commands. The separate PTC Creo License Server components lmadmin and lmgrd are explicitly not affected.
What CVE-2024-6071 affects
The vulnerable component is Creo Elements/Direct License Server (MEls). PTC identifies MEls versions 20.7.0.0 and earlier as affected. Upgrade to 20.7.0.1 or later through PTC’s authenticated download and support channels.
PTC’s broader affected-product listing includes Creo Elements/Direct Drafting 15.00–20.7, Model Manager/Drawing Manager 15.00–20.7, Modeling 15.00–20.7, and WorkManager/DDM 15.00–20.4 where they use the affected licensing server. The patch decision, however, is determined by the MEls server version actually installed in your environment.
Do not patch the wrong license server
PTC states that the separate PTC Creo License Server, using lmadmin or lmgrd, is not affected by this vulnerability. Inventory the service name and product before scheduling a change; an lmadmin/lmgrd host is not the MEls host covered by CVE-2024-6071.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Why this is an emergency
PTC assigns CVE-2024-6071 a CVSS 3.1 score of 10.0 (PTC, 2025), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/H:H/I:H/A:H. In practical terms, the attack is network reachable, has low complexity, needs no account and no user interaction, and can affect confidentiality, integrity and availability.
The advisory describes a missing-authorization condition in MEls’s web interface. An unauthenticated remote attacker may use that interface to execute arbitrary operating-system commands on the server. Any MEls instance reachable from the public internet should therefore be handled as both an urgent patching task and a potential incident-response concern.
Rank #2
Patch version and supported route
- Identify every MEls deployment. Include production, disaster-recovery, test and standby servers, and record the exact installed version and host exposure.
- Classify the version. Treat 20.7.0.0 and every earlier MEls release as affected until upgraded.
- Obtain the update from PTC. Use PTC’s authenticated software-download or support process to obtain Creo Elements/Direct License Server 20.7.0.1 or a later supported release. Do not substitute an unofficial installer.
- Schedule the service change. Follow your organization’s backup, rollback and license-availability procedures. Coordinate with teams whose Creo Elements/Direct applications depend on the server.
- Install and verify. After installation, confirm that the running service reports 20.7.0.1 or later, then test license checkout from representative dependent applications.
- Close the change with evidence. Record the host, old and new versions, installation source, verification result and date in the change-management record.
Exposure checks while the patch is pending
- Determine whether the MEls web interface is reachable from the internet, partner networks, user VLANs or other untrusted segments.
- Restrict access to the interface to required administration networks using firewall or equivalent controls, without assuming that network filtering replaces the upgrade.
- Preserve web-server, operating-system and network logs before making changes that could overwrite evidence.
- Look for unexpected processes, accounts, scheduled tasks, outbound connections, modified license-server files or unexplained configuration changes.
Because the flaw requires neither authentication nor user interaction, do not treat the presence of a login prompt elsewhere in the environment as proof that MEls is protected.
What to do if compromise is possible
If logs or host telemetry show suspicious activity, involve your incident-response team and PTC Technical Support. Isolate the server according to your response plan while preserving forensic evidence, assess credentials and systems reachable from the host, and rebuild or restore from a known-good source when responders require it. Patch validation should follow containment and evidence-preservation decisions rather than destroy evidence through an unplanned reinstall.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
Advisory timing and attribution
PTC’s Trust Center lists advisory ICSA-24-177-02, published July 9, 2024. PTC’s support article shows a modification date of September 3, 2025; check the live PTC article and your support portal before closing change control in case release guidance has changed.
PTC credited Thomas Riedmaier of Siemens Energy with reporting the issue. PTC said it had no indication of exploitation when its article was published. That was a time-limited statement, not a guarantee that exploitation has not occurred since.
Rank #4
Quick decision table
| What you find | Action |
|---|---|
| Creo Elements/Direct License Server (MEls) 20.7.0.0 or earlier | Urgently upgrade to 20.7.0.1 or later through PTC. |
| MEls 20.7.0.1 or later | Confirm the running service version and retain upgrade evidence; monitor PTC for later guidance. |
| PTC Creo License Server using lmadmin or lmgrd | Not affected by CVE-2024-6071 according to PTC; follow separate security and lifecycle guidance. |
| Product or version cannot be identified | Treat the host as potentially affected, restrict exposure, and confirm its identity with PTC support before closing the review. |
Sources to verify before closure
Use PTC’s CVE-2024-6071 support guidance, the PTC Trust Center entry for ICSA-24-177-02, and the corresponding CISA advisory summary. Confirm the current modification date, supported download package and any product-specific installation notes in your authenticated PTC account.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

