Vulnerability record · CVE-2025-0994 · published 6 February 2025
CVE-2025-0994: Trimble Cityworks Deserialization Flaw Enables Remote Code Execution
Trimble · Cityworks
Trimble Cityworks versions prior to 15.8.9 and Cityworks with Office Companion versions prior to 23.10 deserialize untrusted data, allowing an authenticated user to execute arbitrary code on the customer's Microsoft IIS web server. The flaw is remotely reachable over the network and carries high impact to confidentiality, integrity, and availability, making it a serious risk for exposed Cityworks deployments.
Description
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityThe vulnerability is in CISA's Known Exploited Vulnerabilities catalog with active exploitation, has a high CVSS score of 8.6, and allows remote code execution on an internet-facing IIS server.
What it is
Trimble Cityworks versions prior to 15.8.9 and Cityworks with Office Companion versions prior to 23.10 deserialize untrusted data, allowing an authenticated user to execute arbitrary code on the customer's Microsoft IIS web server. The flaw is remotely reachable over the network and carries high impact to confidentiality, integrity, and availability, making it a serious risk for exposed Cityworks deployments.
Impact
An attacker with valid credentials can run arbitrary code on the IIS server hosting Cityworks, potentially leading to full server compromise, data theft, or service disruption.
Attack surface
The vulnerability is network-reachable (AV:N) and requires high privileges (PR:H) with no user interaction (UI:N), meaning an authenticated user with elevated access can trigger it directly against the IIS web server.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-07, indicating active exploitation; EPSS gives a 30-day probability of 0.31309 (98th percentile), and no ransomware campaign use is documented.
What to do
- Upgrade Cityworks to version 15.8.9 or later, and Cityworks with Office Companion to version 23.10 or later, per the vendor advisory.
- If immediate patching is not possible, apply the mitigations in the vendor communication or discontinue use of the product as directed by CISA.
- Restrict network access to the Cityworks IIS web server to trusted networks and limit authenticated accounts to only those that require access.
- Monitor and audit accounts with high privileges that could be used to reach the vulnerable endpoint.
Detection
- Review IIS and application logs for unusual deserialization-related requests or unexpected process creation on the Cityworks web server.
- Hunt for anomalous child processes spawned by the IIS worker process (w3wp.exe) that may indicate remote code execution.
- Monitor for authentication events using high-privilege accounts followed by suspicious server-side activity.
- Use the CISA KEV entry and vendor advisory to validate exposure and prioritize scanning for affected Cityworks versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-0994 to the Known Exploited Vulnerabilities catalog on 7 February 2025 as "Trimble Cityworks Deserialization Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 February 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-05-docx/0? | Vendor Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-037-04 | Third Party AdvisoryUS Government Resource |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-0994 | US Government Resource |
Track CVE-2025-0994 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-0994), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.