Hackers exploiting bug in popular Trimble Cityworks tool used by local gov’ts

Avatar

Federal civilian agencies have been ordered to patch a vulnerability impacting Trimble Cityworks — a popular tool used by many governments to manage public infrastructure. 

The Cybersecurity and Infrastructure Security Agency (CISA) released a warning alongside Trimble on Thursday about CVE-2025-0994 after confirming it is being exploited by hackers. Federal civilian agencies have until February 28 to patch the bug. 

Trimble Cityworks is an asset management system used by many local and federal government agencies to manage infrastructure assets for airports, utilities, municipalities and counties.

CISA said the vulnerability allows malicious actors to “potentially conduct remote code execution (RCE) against a customer’s Microsoft Internet Information Services (IIS) web server.”

In a letter to customers, the company said the notice followed “investigations of reports of unauthorized attempts to gain access to specific customers’ Cityworks deployments.” 

A patch was released on January 29 and the company listed several other actions customers need to take to reduce the exposure of data. Customers should limit permissions connected to Cityworks and the system “should not be run with local or domain level administrative privileges on any site.”

The company also provided indicators of compromise alongside the letter. CISA said Trimble reported the vulnerability to them and Symantec’s Threat Hunter team contributed to the advisory they released about the bug. 

The bug carries a CVSS v4 severity score of 8.4 out of 10. All Cityworks versions prior to 15.8.9 are impacted by the vulnerability. 

Trimble did not respond to requests for comment about what actions the hackers took after exploiting CVE-2025-0994 or where the hackers may be based. 

Trimble is a large Colorado-based technology provider, with more than 11,000 employees across about 40 countries. The company reported a revenue of $875.8 million in the last fiscal quarter. 

The Cityworks tool allows customers to manage critical infrastructure assets from one platform and organize inspections, work orders, permits, operations and more.

About a year ago, agricultural equipment manufacturer AGCO acquired an 85% stake in Trimble’s agribusiness for $2 billion in cash. AGCO suffered a ransomware attack in 2022 that impacted its business operations.

CybercrimeGovernmentIndustryNews BriefsNews
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

 

Total
0
Shares
Previous Post

Label maker Avery says ransomware investigation also found credit-card scraper

Next Post

8Base ransomware site taken down as Thai authorities arrest 4 connected to operation

Related Posts

Phishers Exploit Google Sites and DKIM Replay to Send Signed Emails, Steal Credentials

In what has been described as an "extremely sophisticated phishing attack," threat actors have leveraged an uncommon approach that allowed bogus emails to be sent via Google's infrastructure and redirect message recipients to fraudulent sites that harvest their credentials. "The first thing to note is that this is a valid, signed email – it really was sent from no-reply@google.com," Nick Johnson
Avatar
Read More

Pakistan-Linked Hackers Expand Targets in India with CurlBack RAT and Spark RAT

A threat actor with ties to Pakistan has been observed targeting various sectors in India with various remote access trojans like Xeno RAT, Spark RAT, and a previously undocumented malware family called CurlBack RAT. The activity, detected by SEQRITE in December 2024, targeted Indian entities under railway, oil and gas, and external affairs ministries, marking an expansion of the hacking crew's
Avatar
Read More