logo

Hackers exploit Cityworks RCE bug to breach Microsoft IIS servers

ID: 636322a5-94d2-54fb-9271-9748b8779cb4

STIX ID: report--636322a5-94d2-54fb-9271-9748b8779cb4

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-02-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Trimble and CISA warn that a high-severity deserialization vulnerability (CVE-2025-0994) in Cityworks (affecting versions prior to 15.8.9 and office companion versions before 23.10) is being exploited to achieve RCE on IIS servers; attackers have deployed tools including Cobalt Strike and WinPutty. Trimble has published IOCs and remediation steps (apply patches, fix IIS identity permissions, restrict attachment directories), cloud instances will be auto-updated, and administrators of on-premise deployments are urged to patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.