EXPOSURES › CVE-2025-0994
CVE-2025-0994
HIGH ⌖ ON CISA KEV · EXPLOITEDTrimble Cityworks contains a deserialization vulnerability actively exploited to achieve remote code execution against IIS web servers, impacting DIB organizations using the software.
A deserialization vulnerability in Trimble Cityworks allows authenticated users to execute arbitrary code on vulnerable IIS web servers, posing a significant risk of compromise and potentially impacting NIST 800-171 compliance. DIB organizations using Cityworks must immediately assess their exposure, apply available patches, and review access controls. Failure to do so could lead to data breaches and regulatory penalties.
Shame score — The active exploitation of a deserialization vulnerability, enabling remote code execution, demonstrates a significant security oversight with potentially widespread impact.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.