CISA Warns of Active Exploitation in Trimble Cityworks Vulnerability Leading to IIS RCE
- Posted on February 7, 2025
- By The Hacker News
- 4 Views
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZsyQSd6bFNivpG4VIPqsnw73g1X5HP06a7hN1d47EJuDgyVZiylW-CUJ-yhgjEMSZzBebWh3HC4NlXusIzG7eekqwhjmYVdcrYMasXYYKphVqtSZSF0TSIEgaEeu_ikV0YLc38vYMy6BPnDDWgGwByQvhvJHIR2C7SAmB9AFivt78NLozVdjqbdx80ZM/s728-rw-e365/cityworks-exploit.png)
CISA Warns of Active Exploitation in Trimble Cityworks Vulnerability Leading to IIS RCE
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZsyQSd6bFNivpG4VIPqsnw73g1X5HP06a7hN1d47EJuDgyVZiylW-CUJ-yhgjEMSZzBebWh3HC4NlXusIzG7eekqwhjmYVdcrYMasXYYKphVqtSZSF0TSIEgaEeu_ikV0YLc38vYMy6BPnDDWgGwByQvhvJHIR2C7SAmB9AFivt78NLozVdjqbdx80ZM/s728-rw-e365/cityworks-exploit.png)
CISA warns of active attacks exploiting Trimble Cityworks CVE-2025-0994 (CVSS 8.6). Hackers deploy Rust-based malware, Cobalt Strike, and VShell.