CVE-2025-0994 - CVE House
Back to Database
Status published High CVE-2025-0994

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office...

Vulnerability Description

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0994

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Trimble

Affected Vendor

Affected Software

Cityworks, Cityworks (with office companion)
Vulnerable Versions:
0

Timeline

Official Publish: February 6th, 2025
Last Modified: October 21st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)