Description

Trimble has issued a critical cybersecurity advisory regarding CVE-2025-0994, a high-risk deserialization flaw impacting its Cityworks asset and work management platform. With a CVSS score of 7.2, this vulnerability enables authenticated attackers to execute arbitrary code on Microsoft IIS web servers hosting the software. Versions before 15.8.9 and Cityworks Office Companion prior to 23.10 are particularly susceptible. Security experts and CISA have confirmed active exploitation, urging organizations to take immediate protective measures. Trimble has released patches to address the vulnerability, advising on-premises customers to upgrade to version 15.8.9 for the 15.x series and 23.10 for the 23.x series without delay. Cityworks Online (CWOL) users will automatically receive updates, minimizing exposure. The company further recommends reviewing IIS identity permissions and attachment directory configurations, as improper settings could escalate the impact of an attack. Given the critical nature of this threat, organizations using Cityworks must swiftly implement mitigation strategies to prevent system compromises, data theft, or service disruptions. CISA continues to monitor exploitation activity and stresses the importance of timely updates, proper configuration management, and persistent network monitoring to defend against potential cyberattacks.