You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-0994
About this tag
CVE-2025-0994 is a critical deserialization vulnerability affecting Trimble Cityworks, an asset management system used in critical infrastructure sectors like water and wastewater. The Cybersecurity and Infrastructure Security Agency (CISA) added it to the Known Exploited Vulnerabilities Catalog in February 2025. The flaw allows remote code execution on Microsoft Internet Information Services (IIS) web servers running vulnerable Cityworks versions prior to 23.10. Windows administrators managing these systems should apply Trimble's security updates immediately to prevent exploitation. Discussions on WindowsForum cover the vulnerability's impact, mitigation steps, and broader cybersecurity implications for Windows-based enterprise environments.
In a significant update for cybersecurity, the Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities Catalog. The latest entrant is CVE-2025-0994, identified as the Trimble Cityworks Deserialization Vulnerability. Although...
On February 7, 2025, security officials sounded the alarm as Trimble issued important updates to counter a newly discovered vulnerability in its Cityworks Server AMS (Asset Management System). This vulnerability, identified as CVE-2025-0994, has raised concerns among administrators managing...
A recent advisory from CISA has shed light on a serious vulnerability affecting Trimble Cityworks, an asset and work management system popular in critical infrastructure sectors such as water and wastewater systems. If you’re responsible for deploying or managing Windows systems tied to Trimble...