CVE-2025-0994: Trimble Cityworks Deserialization Vulnerability
Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.
Other sources
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Trimble Cityworksto a version that resolves this vulnerability.Fixed in 15.8.9 - Upgrade
Upgrade
Trimble Cityworks with office companionto a version that resolves this vulnerability.Fixed in 23.10 - Upgrade
Upgrade
Trimble Cityworksto a version that resolves this vulnerability.Fixed in 23.10
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0994?
CVE-2025-0994 is considered to be a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-0994?
To fix CVE-2025-0994, upgrade to Trimble Cityworks version 23.10 or later.
Who is affected by CVE-2025-0994?
CVE-2025-0994 affects users of Trimble Cityworks versions prior to 23.10.
What type of vulnerability is CVE-2025-0994?
CVE-2025-0994 is a deserialization vulnerability that can lead to remote code execution.
Can an unauthenticated user exploit CVE-2025-0994?
No, only authenticated users can exploit CVE-2025-0994 to perform a remote code execution attack.