Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-0994 | Authenticated Deserialization RCE in Trimble Cityworks Trimble Cityworks, a GIS-based asset management platform used largely by local governments and utilities, contains a deserialization vulnerability (CWE-502). An authenticated user triggers the flaw by submitting maliciously crafted serialized input to the Cityworks web application. Successful exploitation yields remote code execution on the underlying Microsoft IIS web server hosting the product. Any organization running Cityworks on IIS is affected, especially where the server is internet-facing. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-07, confirming exploitation in the wild; no public PoC is known, CVSS scoring is pending, and EPSS assigns roughly a 31% probability of exploitation within 30 days. Do: Patch or apply Trimble's mitigations to all Cityworks/IIS servers per vendor instructions, as required by the CISA KEV listing, and discontinue use if mitigations are unavailable. Because exploitation requires authentication, review and rotate Cityworks accounts and credentials, and inspect IIS/application logs on exposed servers for signs of compromise (ransomware use is unconfirmed but possible). | 8.6 | 31% | KEV |
| nicheroughly hundreds to low thousands of deployments, concentrated at local governments, utilities and public agencies (estimate; no public install counts… |
Full article192 words · extracted from blog.talosintelligence.com · click to collapse
June 26, 2025 06:00
Decrement by one to rule them all: AsIO3.sys driver exploitation
Cisco Talos uncovered and analyzed two critical vulnerabilities in ASUS' AsIO3.sys driver, highlighting serious security risks and the importance of robust driver design.
By Marcin Noga
May 22, 2025 06:00
UAT-6382 exploits Cityworks zero-day vulnerability to deliver malware
Talos has observed exploitation of CVE-2025-0994 in the wild by UAT-6382, a Chinese-speaking threat actor, who then deployed malware payloads via TetraLoader.
December 19, 2024 06:04
Exploring vulnerable Windows drivers
This post is the result of research into the real-world application of the Bring Your Own Vulnerable Driver (BYOVD) technique along with Cisco Talos’ series of posts about malicious Windows drivers.
October 8, 2024 15:04
Largest Patch Tuesday since July includes two exploited in the wild, three critical vulnerabilities
The two vulnerabilities that Microsoft reports have been actively exploited in the wild and are publicly known are both rated as only being of “moderate” severity.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/category/vulnerability/