EUVD-2025-1955
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 7 Feb 2025. Evidence sources: cisa_kev.
- ENISA score
- 8.6 · CVSS 4.0
- Advisory evidence
- 1 linked advisory record
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_cisa · ICSA-25-037-04Trimble Cityworks (Update A)
