Junglewise Threat Intelligence

CVE-2025-0994: Trimble Cityworks Deserialization Vulnerability

CVE-2025-0994 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-02-07

Vendors: Trimble.

Executive brief

Trimble Cityworks contains a deserialization of untrusted data vulnerability (CWE-502). An authenticated attacker can exploit this flaw to achieve remote code execution on the underlying Microsoft Internet Information Services (IIS) web server.

Affected products

  • Trimble Cityworks prior to 15.8.9
  • Trimble Cityworks with Office Companion prior to 23.10

Timeline

  • 2025-02-05: advisory: Vendor advisory released by Trimble.
  • 2025-02-06: disclosed: NVD Published Date.
  • 2025-02-07: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
  • 2025-02-07: exploited: Reported as exploited in the wild.