CVE-2025-0994

Confirmed PUBLISHED

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization...

Trimble · Cityworks, Cityworks (with office companion)
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.6 High

At a Glance

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.

cisa
CVE Published
Feb 06, 2025
Exploitation Reported
Feb 07, 2025
CVSS
8.6 High
EPSS
Remote Low complexity No user interaction

Affected Versions

Vendor Product Version Status
Trimble
Cityworks

0 to < 15.8.9

Affected
Trimble
Cityworks (with office companion)

0 to < 23.10

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.