Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Trimble Cityworks Customers Warned of Zero-Day Exploitation

Trimble Cityworks is affected by a zero-day vulnerability that has been exploited in attacks involving the delivery of malware.

Trimble Cityworks zero-day CVE-2025-0994

US-based construction, geospatial and transportation technology solutions provider Trimble has warned customers of its Cityworks product about a vulnerability that has been exploited in the wild.

The zero-day, tracked as CVE-2025-0994 and classified as ‘high severity’, has been described as a deserialization issue that allows an external threat actor to achieve remote code execution against the target’s Microsoft Internet Information Services (IIS) web server.

Trimble Cityworks is a GIS-centric solution that organizations such as local governments, airports, utilities, and public works agencies can use to manage and maintain infrastructure. The product has been used by organizations worldwide.

The cybersecurity agency CISA has published an industrial control systems (ICS) advisory for CVE-2025-0994, likely due to its use in the industrial sector, but noted that the “Cityworks software is incapable of controlling industrial processes, and is not directly part of an ICS”.

CISA’s advisory also reveals that authentication is required to exploit the vulnerability. 

Based on the indicators of compromise (IoCs) made available by Trimble, the threat actors exploiting the Cityworks zero-day have delivered Cobalt Strike and several unidentified pieces of malware in post-exploitation activity.  

Save the date: 2025 ICS Cyber Security Conference – October 27-30, Atlanta

It’s unclear who is behind the attacks and what types of entities have been targeted. However, Trimble received reports of “unauthorized attempts to gain access to specific customers’ Cityworks deployments”. In addition, given the types of organizations Cityworks is designed for, the zero-day has likely been exploited in targeted attacks.

Advertisement. Scroll to continue reading.

The vendor pointed out that some on-premises deployments have overprivileged IIS permissions. In addition, some deployments have inappropriate attachment directory configurations. Customers have been urged to address these issues. 

Trimble has patched CVE-2025-0994 with the release of Cityworks 15.8.9 and 23.10 (with office companion). Previous versions of the software are affected.

Related: Cyber Insights 2025: OT Security

Related: Rockwell Patches Critical, High-Severity Vulnerabilities in Several Products

Related: Building Automation Protocols Increasingly Targeted in OT Attacks

Related: Researcher Says ABB Building Control Products Affected by 1,000 Vulnerabilities

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this event as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack.

Register

Learn how integrating BAS and Automated Penetration Testing empowers security teams to quickly identify and validate threats, enabling prompt response and remediation.

Register

People on the Move

SplxAI, a startup focused on securing AI agents, has announced new CISO Sandy Dunn.

Phillip Miller is joining tax preparation giant H&R Block as VP and CISO.

Linx Security has appointed Sarit Reiner Frumkes as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.