CVE-2025-0994

CVSS 3.1 Score 8.8 of 10 (high)

Attack Complexity low
Confidentiality high
Integrity high
Availability high
Privileges Required low
Scope unchanged

Details

Published Feb 6, 2025
Updated: Feb 12, 2025
CWE ID 502

Summary

CVE-2025-0994 is a deserialization vulnerability affecting Trimble Cityworks versions below 15.8.9 and Cityworks with office companion versions prior to 23.10. An authenticated user can exploit this issue to execute remote code on a customer's Microsoft Internet Information Services (IIS) web server. This vulnerability poses a severe risk, particularly for organizations using these Cityworks versions, as it could lead to unauthorized system takeover and potential data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Trimble Cityworks

Affected Vendors

  • Trimble Inc.