CISA Alerts About Ongoing Exploitation in Trimble Cityworks Vulnerability Resulting in IIS Remote Code Execution
It has been cautioned by the Cybersecurity and Infrastructure Security Agency (CISA) of the United States that a security vulnerability in Trimble Cityworks GIS-centric asset management software is currently being actively exploited in real-world scenarios.
The specific vulnerability referred to is CVE-2025-0994 (CVSS v4 score: 8.6), a flaw in handling untrusted data deserialization that may allow an intruder to execute code remotely.
“This situation may result in
The specific vulnerability referred to is CVE-2025-0994 (CVSS v4 score: 8.6), a flaw in handling untrusted data deserialization that may allow an intruder to execute code remotely.
“This situation may result in
