• News/
  • https://www.bleepingcomputer.com/news/security/hackers-exploit-cityworks-rce-bug-to-breach-microsoft-iis-servers/

Hackers exploit Cityworks RCE bug to breach Microsoft IIS servers

BleepingComputer
·
Bill Toulas
·
Published Feb 7, 2025
·
Updated

Software vendor Trimble is warning that hackers are exploiting a Cityworks deserialization vulnerability to remotely execute commands on IIS servers and deploy Cobalt Strike beacons for initial network access. Trimble Cityworks is a Geographic Information System (GIS)-centric asset management and work order management software designed primarily for local governments, utilities, and public works organizations. The product helps municipalities and infrastructure agencies manage public assets, process work orders, handle permitting and licensing, capital planning, and budgeting, among other things. The flaw, tracked as CVE-2025-0994, is a high severity (CVSS v4.0 score: 8.6) deserialization problem that allows authenticated users to perform RCE attacks against a customer's Microsoft Internet Information Services (IIS) servers. Trimble states that it has investigated customer reports about hackers gaining unauthorized access to customer networks by leveraging the flaw, indicating that exploitation is underway. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a coordinated advisory warning customers to immediately secure their networks from attacks. The CVE-2025-0994 flaw impacts Cityworks versions prior to 15.8.9 and Cityworks with office companion versions before 23.10. The latest versions, 15.8.9 and 23.10, were made available on January 28 and 29, 2025, respectively. Administrators managing on-premise deployments must apply the security update as...

Read full article

Affected Software

3 affected components
Trimble Cityworks=15.8.9
Trimble Cityworks with Office Companion=23.10
Trimble Cityworks
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how hackers are exploiting a remote code execution vulnerability in Trimble City's Cityworks software to breach Microsoft IIS servers.

2

What security implications are discussed in the article?

The article highlights the risk of remote command execution on IIS servers and the deployment of Cobalt Strike beacons for initial network access.

3

Which software products are affected by the vulnerability?

The affected software includes Trimble Cityworks version 15.8.9 and Trimble Cityworks with Office Companion version 23.10.

4

What type of vulnerability is being exploited by the attackers?

The vulnerability being exploited is a deserialization vulnerability in Trimble Cityworks.

5

Who is the software vendor warning about the exploitation?

The software vendor warning about the exploitation is Trimble.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203