>> All posts

CVE-2025-0994: Trimble Cityworks deserialization RCE, actively exploited

The short version: Trimble Cityworks — asset and work-order management used heavily by local governments and utilities — has a deserialization flaw (CVE-2025-0994) that lets an authenticated user execute code on the underlying Microsoft IIS web server. It's been exploited in the wild, it's in CISA's KEV catalog, and fixes exist. If you run Cityworks, patch and verify. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — in practice (see below)
CVSS v3.1 (NVD)8.8 — High · AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS~31.3% · 98.1th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2025-02-28
Known exploited?Yes — exploited in the wild against local-government/utility environments
Vulnerability typeCWE-502 deserialization of untrusted data → remote code execution on the IIS server
Requires authenticated session?Yes — an authenticated user (low privilege)
AffectedCityworks before 15.8.9; Cityworks with office companion before 23.10
Fixed in15.8.9 · 23.10 (and later)

What you need to know

CVE-2025-0994 is a deserialization vulnerability in Trimble Cityworks. An authenticated user can submit crafted serialized data that the application unsafely deserializes, resulting in remote code execution against the customer's Microsoft IIS web server that hosts the application.

The reason the practical severity is high despite the authentication requirement:

  • The target is a public-sector operations platform. Cityworks runs the asset, permitting, and work-order backbone for many municipalities and utilities — code execution on its web server reaches sensitive operational systems.
  • It was exploited in the wild. CISA issued an ICS advisory and added it to KEV; threat actors used it for hands-on-keyboard access, so an exposed, unpatched instance may already have been targeted.
  • Authentication is a barrier, not a wall. Where account access is easy to obtain, the requirement offers little protection.

How serious we see it

High — in practice, above the 8.8 base.

Code execution on the IIS server behind a widely deployed local-government platform, confirmed exploited and KEV-listed, is top-of-queue even with the authenticated-user requirement. We rate it by impact and real-world use. The bounded, reassuring part is that it's specific and fixed: Cityworks before 15.8.9 (and companion before 23.10), with published fixes and clear vendor and CISA guidance.

Recommendations

Straight from Trimble's advisory and CISA:

  1. Patch now. Upgrade Cityworks to 15.8.9 (and office companion to 23.10) or later.
  2. Follow Trimble's hardening guidance. Correct IIS identity/privilege configuration so the application isn't running with excessive rights, per the vendor communication.
  3. Hunt for prior use. Review for indicators of compromise and web-shell activity on the IIS server.
  4. If compromised, respond. Rebuild where warranted and rotate credentials and secrets the server could reach.
  5. Confirm your exposure first. Verify whether you run Cityworks and which build.

How BreachRisk sees it

BreachRisk discovers internet-facing Cityworks portals from the outside, fingerprints the product and version, and flags exposure tied to this KEV-listed, actively exploited CVE so it rises to the top of your results. Because exploitation here requires an authenticated session, BreachRisk detects and prioritizes the exposure rather than exercising it — separating discovery and flagging from any active test. The value is that an exposed, affected Cityworks is already on your map when the flaw matters.

References

See your cyber risk, proven.