¡¾Îó²îͨ¸æ¡¿Trimble Cityworks·´ÐòÁл¯Îó²î(CVE-2025-0994)

Ðû²¼Ê±¼ä 2025-02-11

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Trimble Cityworks·´ÐòÁл¯Îó²î

CVE   ID

CVE-2025-0994

Îó²îÀàÐÍ

·´ÐòÁл¯

·¢Ã÷ʱ¼ä

2025-02-11

Îó²îÆÀ·Ö

8.6

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Trimble CityworksÊÇÒ»¿î»ùÓÚµØÀíÐÅϢϵͳ£¨GIS£©µÄ×ʲúÖÎÀíƽ̨£¬×¨Îª¹«¹²ÉèÊ©ÖÎÀí¡¢¶¼»áÍýÏëºÍ»ù´¡Éèʩά»¤Éè¼Æ ¡£ËüÌṩÖÜÈ«µÄ½â¾ö¼Æ»®£¬×ÊÖúÕþ¸®ºÍÆóÒµÓÐÓÃÖÎÀí×ʲú¡¢Î¬»¤ÉèÊ©¡¢ÓÅ»¯ÊÂÇéÁ÷³Ì£¬²¢ÌáÉýÔËӪЧÂÊ ¡£Í¨¹ýÓëGISÊÖÒյļ¯³É£¬CityworksÄܹ»ÊµÏÖ׼ȷµÄ¿Õ¼äÊý¾ÝÖÎÀí£¬Ö§³ÖÖÇÄܾöæźÍ×ÊÔ´·ÖÅÉ ¡£


2025Äê2ÔÂ11ÈÕ£¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¼¯ÍÅVSRC¼à²âµ½TrimbleÐû²¼µÄCityworks°²ÅÅÏà¹ØÇ徲ͨ¸æ ¡£Í¨¸æÏÔʾ£¬Cityworks 15.8.9֮ǰµÄ°æ±¾¼°Cityworks with Office Companion 23.10֮ǰµÄ°æ±¾±£´æ¸ßΣ·´ÐòÁл¯Îó²î£¨CVE-2025-0994£© ¡£¸ÃÎó²îÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ¿Í»§µÄMicrosoft Internet Information Services£¨IIS£©·þÎñÆ÷ÉÏÖ´ÐÐÔ¶³Ì´úÂ루RCE£©£¬¿ÉÄܵ¼ÖÂϵͳ±»¿ØÖƲ¢Î£¼°Êý¾ÝÇå¾² ¡£


¶þ¡¢Ó°Ïì¹æÄ£


Cityworks < 15.8.9
Cityworks with Office Companion < 23.10


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Éý¼¶ÖÁCityworks 15.8.9»ò¸üа汾
Éý¼¶ÖÁCityworks with Office Companion 23.10»ò¸üа汾


ÏÂÔØÁ´½Ó£º

https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?


3.2 ÔÝʱ²½·¥


¼ì²éIIS·þÎñÆ÷ȨÏÞ£¬×èֹʹÓÃÍâµØ»òÓò¼¶ÖÎÀíԱȨÏÞ ¡£

ÓÅ»¯¸½¼þĿ¼ÉèÖ㬽öÔÊÐí´æ´¢¸½¼þÎļþ ¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ïÔ̭ϵͳÎó²î£¬ÌáÉý·þÎñÆ÷µÄÇå¾²ÐÔ ¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬Ð޸ķÀ»ðǽսÂÔ£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻò·þÎñ£¬ïÔÌ­½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ïÔÌ­¹¥»÷Ãæ ¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ ¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöàÒòËØÈÏÖ¤»úÖƺÍ×îСȨÏÞÔ­Ôò£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È ¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐÞ¸Ä ¡£


3.4 ²Î¿¼Á´½Ó


https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://www.cisa.gov/news-events/ics-advisories/icsa-25-037-04
https://nvd.nist.gov/vuln/detail/CVE-2025-0994
https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-05-docx/0?