Trimble Cityworks: CVE-2025-0994
ID: eebdd2a1-c8f1-5ad2-9ea3-d9be50774c7f
STIX ID: report--eebdd2a1-c8f1-5ad2-9ea3-d9be50774c7f
Feed Name: Recorded Future Blog
Threat Score
Recorded Future’s Insikt Group details CVE-2025-0994, a high-severity deserialization vulnerability in Trimble Cityworks that allows authenticated remote code execution against IIS. The report notes active exploitation delivering Rust-based loaders, VShell and Cobalt Strike, provides IoCs (including C2 IPs), cites 111 exposed Cityworks instances with a portion vulnerable, and recommends immediate patching to versions 15.8.9/23.10 or later with reference to CISA guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
