CVE-2025-0994
CVSS 3.1 Score 8.8 of 10 (high)
Attack Complexity low
Confidentiality high
Integrity high
Availability high
Privileges Required low
Scope unchanged
Details
Published Feb 6, 2025
Updated: Feb 12, 2025
CWE ID 502
Summary
CVE-2025-0994 is a deserialization vulnerability affecting Trimble Cityworks versions below 15.8.9 and Cityworks with office companion versions prior to 23.10. An authenticated user can exploit this issue to execute remote code on a customer's Microsoft Internet Information Services (IIS) web server. This vulnerability poses a severe risk, particularly for organizations using these Cityworks versions, as it could lead to unauthorized system takeover and potential data breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Trimble Cityworks
Affected Vendors
- Trimble Inc.