HomeSecurityTrimble Cityworks Customers Warned of Zero-Day

Trimble Cityworks Customers Warned of Zero-Day

Trimble , the American technology solutions company for construction, geospatial data and transportation, has informed customers of its Cityworks software about the existence of a zero-day vulnerability , which has already been exploited in real-world conditions.

See also: Zyxel zero-day vulnerability allows execution of arbitrary commands

Trimble Cityworks Zero-Day

The zero-day bug, codenamed CVE-2025-0994, which has been rated as "high severity," is a vulnerability that allows malicious actors to execute remote code on a Microsoft Internet Information Services (IIS) . This vulnerability is related to a memory management issue, making the server vulnerable to attacks.

Trimble Cityworks is an innovative GIS-based solution designed to serve organizations such as local governments, airports, utilities and public works agencies. The platform offers comprehensive tools for managing and maintaining infrastructure, making processes more efficient and effective. Organizations from every corner of the world have already leveraged Trimble Cityworks, underscoring the global value and reliability of this technology.

The cybersecurity agency CISA issued a statement regarding the vulnerability CVE-2025-0994 affecting Industrial Control Systems (ICS), noting its possible connection to the industrial sector. However, it clarified that “Cityworks software does not have the ability to control industrial processes and is not directly part of an ICS.”

The CISA guidance emphasizes that exploiting the vulnerability requires an authentication process.

See also: Ivanti Zero-Day breaches UK domain registry

According to the indicators of compromise (IoC) published by Trimble, cybercriminals exploiting the Cityworks zero-day vulnerability have deployed Cobalt Strike, as well as several unknown types of malware. These attacks are being carried out as part of their activities following the exploitation of the vulnerability, thus increasing the risk of the situation.

Trimble Cityworks Customers Warned of Zero-Day

It is unclear who is behind the attacks and what types of entities have been targeted. However, Trimble has received reports of “unauthorized attempts to gain access to certain customers’ Cityworks installations.” Furthermore, given the types of organizations Cityworks is designed for, the zero-day has likely been exploited in targeted attacks.

The vendor has pointed out that some on-premises deployments have IIS super-privileged permissions. Additionally, some deployments have improper attachment directory configurations. Customers have been encouraged to address these issues.

Trimble has patched CVE-2025-0994 with the release of Cityworks 15.8.9 and 23.10. Previous versions of the software are affected.

See also: Ivanti zero-day attacks spread custom malware

Zero-day exploits refer to cyberattacks that exploit vulnerabilities in software or systems that are unknown to the vendor or developer. These vulnerabilities are called “zero-day” because developers had zero days to address and fix the flaw before exploiting it. Such attacks are extremely dangerous as they often bypass security measures, giving attackers unauthorized access to sensitive data or systems. They are often used by advanced persistent threat (APT) groups, and combating them requires constant vigilance, advanced tools , and prompt security updates.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS