Executive brief
Trimble Cityworks contains a deserialization of untrusted data vulnerability (CWE-502). An authenticated attacker can exploit this flaw to achieve remote code execution on the underlying Microsoft Internet Information Services (IIS) web server.
Affected products
- Trimble Cityworks prior to 15.8.9
- Trimble Cityworks with Office Companion prior to 23.10
Timeline
- 2025-02-05: advisory: Vendor advisory released by Trimble.
- 2025-02-06: disclosed: NVD Published Date.
- 2025-02-07: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2025-02-07: exploited: Reported as exploited in the wild.