← Vulnerability feed

Vulnerability record · CVE-2025-0994 · published 6 February 2025

CVE-2025-0994: Trimble Cityworks Deserialization Flaw Enables Remote Code Execution

Trimble · Cityworks

Trimble Cityworks versions prior to 15.8.9 and Cityworks with Office Companion versions prior to 23.10 deserialize untrusted data, allowing an authenticated user to execute arbitrary code on the customer's Microsoft IIS web server. The flaw is remotely reachable over the network and carries high impact to confidentiality, integrity, and availability, making it a serious risk for exposed Cityworks deployments.

8.6 CVSS 4.0 High CISA KEV since 7 Feb 2025 EPSS 31% · top 1.8% CWE-502 · Deserialization of untrusted data
8.6CVSS 4.0 base score
31%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe vulnerability is in CISA's Known Exploited Vulnerabilities catalog with active exploitation, has a high CVSS score of 8.6, and allows remote code execution on an internet-facing IIS server.

What it is

Trimble Cityworks versions prior to 15.8.9 and Cityworks with Office Companion versions prior to 23.10 deserialize untrusted data, allowing an authenticated user to execute arbitrary code on the customer's Microsoft IIS web server. The flaw is remotely reachable over the network and carries high impact to confidentiality, integrity, and availability, making it a serious risk for exposed Cityworks deployments.

Impact

An attacker with valid credentials can run arbitrary code on the IIS server hosting Cityworks, potentially leading to full server compromise, data theft, or service disruption.

Attack surface

The vulnerability is network-reachable (AV:N) and requires high privileges (PR:H) with no user interaction (UI:N), meaning an authenticated user with elevated access can trigger it directly against the IIS web server.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-07, indicating active exploitation; EPSS gives a 30-day probability of 0.31309 (98th percentile), and no ransomware campaign use is documented.

What to do

  • Upgrade Cityworks to version 15.8.9 or later, and Cityworks with Office Companion to version 23.10 or later, per the vendor advisory.
  • If immediate patching is not possible, apply the mitigations in the vendor communication or discontinue use of the product as directed by CISA.
  • Restrict network access to the Cityworks IIS web server to trusted networks and limit authenticated accounts to only those that require access.
  • Monitor and audit accounts with high privileges that could be used to reach the vulnerable endpoint.

Detection

  • Review IIS and application logs for unusual deserialization-related requests or unexpected process creation on the Cityworks web server.
  • Hunt for anomalous child processes spawned by the IIS worker process (w3wp.exe) that may indicate remote code execution.
  • Monitor for authentication events using high-privilege accounts followed by suspicious server-side activity.
  • Use the CISA KEV entry and vendor advisory to validate exposure and prioritize scanning for affected Cityworks versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-0994 to the Known Exploited Vulnerabilities catalog on 7 February 2025 as "Trimble Cityworks Deserialization Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 February 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-0994 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed8.8CVE-2026-45659Microsoft SharePoint Server deserialization flaw enables remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an authenticated attacker run code over the network. The flaw is remotely reachable,…KEVEPSS 2.7%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed9.3CVE-2026-45247Mirasvit Full Page Cache Warmer for Magento 2 PHP object injection RCEMirasvit Full Page Cache Warmer for Magento 2 before 1.11.12 passes the CacheWarmer cookie to PHP's native unserialize() without restriction, allowin…KEVEPSS 2.1%analysed8.8CVE-2023-21529Microsoft Exchange Server deserialization flaw enables remote code executionCVE-2023-21529 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft Exchange Server that allows remote code execution. It carr…KEVEPSS 59%analysed

Source: NIST National Vulnerability Database (record CVE-2025-0994), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.