Software vendor Trimble is warning that hackers are exploiting a Cityworks deserialization vulnerability to remotely execute commands on IIS servers and deploy Cobalt Strike beacons for initial network access. Trimble Cityworks is a Geographic Information System (GIS)-centric asset management and work order management software designed primarily for local governments, utilities, and public works organizations. The product helps municipalities and infrastructure agencies manage public assets, process work orders, handle permitting and licensing, capital planning, and budgeting, among other things. The flaw, tracked as CVE-2025-0994, is a high severity (CVSS v4.0 score: 8.6) deserialization problem that allows authenticated users to perform RCE attacks against a customer's Microsoft Internet Information Services (IIS) servers. Trimble states that it has investigated customer reports about hackers gaining unauthorized access to customer networks by leveraging the flaw, indicating that exploitation is underway. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a coordinated advisory warning customers to immediately secure their networks from attacks. The CVE-2025-0994 flaw impacts Cityworks versions prior to 15.8.9 and Cityworks with office companion versions before 23.10. The latest versions, 15.8.9 and 23.10, were made available on January 28 and 29, 2025, respectively. Administrators managing on-premise deployments must apply the security update as...
Hackers exploit Cityworks RCE bug to breach Microsoft IIS servers
BleepingComputer
·Bill Toulas
·Published Feb 7, 2025
·Updated
Affected Software
3 affected components
Trimble Cityworks=15.8.9
Trimble Cityworks with Office Companion=23.10
Trimble Cityworks
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how hackers are exploiting a remote code execution vulnerability in Trimble City's Cityworks software to breach Microsoft IIS servers.
2
What security implications are discussed in the article?
The article highlights the risk of remote command execution on IIS servers and the deployment of Cobalt Strike beacons for initial network access.
3
Which software products are affected by the vulnerability?
The affected software includes Trimble Cityworks version 15.8.9 and Trimble Cityworks with Office Companion version 23.10.
4
What type of vulnerability is being exploited by the attackers?
The vulnerability being exploited is a deserialization vulnerability in Trimble Cityworks.
5
Who is the software vendor warning about the exploitation?
The software vendor warning about the exploitation is Trimble.