¡¾Îó²îͨ¸æ¡¿Trimble Cityworks·´ÐòÁл¯Îó²î(CVE-2025-0994)

Ðû²¼Ê±¼ä 2025-02-11

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Trimble Cityworks·´ÐòÁл¯Îó²î

CVE   ID

CVE-2025-0994

Îó²îÀàÐÍ

·´ÐòÁл¯

·¢Ã÷ʱ¼ä

2025-02-11

Îó²îÆÀ·Ö

8.6

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Trimble CityworksÊÇÒ»¿î»ùÓÚµØÀíÐÅϢϵͳ£¨GIS£©µÄ×ʲúÖÎÀíÆ½Ì¨£¬£¬£¬£¬£¬×¨Îª¹«¹²ÉèÊ©ÖÎÀí¡¢¶¼»áÍýÏëºÍ»ù´¡Éèʩά»¤Éè¼Æ¡£¡£¡£¡£¡£¡£¡£ËüÌṩÖÜÈ«µÄ½â¾ö¼Æ»®£¬£¬£¬£¬£¬×ÊÖúÕþ¸®ºÍÆóÒµÓÐÓÃÖÎÀí×ʲú¡¢Î¬»¤ÉèÊ©¡¢ÓÅ»¯ÊÂÇéÁ÷³Ì£¬£¬£¬£¬£¬²¢ÌáÉýÔËӪЧÂÊ¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÓëGISÊÖÒյÉ£¬£¬£¬£¬£¬CityworksÄܹ»ÊµÏÖ׼ȷµÄ¿Õ¼äÊý¾ÝÖÎÀí£¬£¬£¬£¬£¬Ö§³ÖÖÇÄܾöæÅºÍ×ÊÔ´·ÖÅÉ¡£¡£¡£¡£¡£¡£¡£


2025Äê2ÔÂ11ÈÕ£¬£¬£¬£¬£¬¼øºÚµ£±£Íø¼¯ÍÅVSRC¼à²âµ½TrimbleÐû²¼µÄCityworks°²ÅÅÏà¹ØÇ徲ͨ¸æ¡£¡£¡£¡£¡£¡£¡£Í¨¸æÏÔʾ£¬£¬£¬£¬£¬Cityworks 15.8.9֮ǰµÄ°æ±¾¼°Cityworks with Office Companion 23.10֮ǰµÄ°æ±¾±£´æ¸ßΣ·´ÐòÁл¯Îó²î£¨CVE-2025-0994£©¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ¿Í»§µÄMicrosoft Internet Information Services£¨IIS£©Ð§ÀÍÆ÷ÉÏÖ´ÐÐÔ¶³Ì´úÂ루RCE£©£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂϵͳ±»¿ØÖƲ¢Î£¼°Êý¾ÝÇå¾²¡£¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Cityworks < 15.8.9
Cityworks with Office Companion < 23.10


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Éý¼¶ÖÁCityworks 15.8.9»ò¸üа汾
Éý¼¶ÖÁCityworks with Office Companion 23.10»ò¸üа汾


ÏÂÔØÁ´½Ó£º

https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?


3.2 ÔÝʱ²½·¥


¼ì²éIISЧÀÍÆ÷ȨÏÞ£¬£¬£¬£¬£¬×èֹʹÓÃÍâµØ»òÓò¼¶ÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£¡£

ÓÅ»¯¸½¼þĿ¼ÉèÖ㬣¬£¬£¬£¬½öÔÊÐí´æ´¢¸½¼þÎļþ¡£¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://www.cisa.gov/news-events/ics-advisories/icsa-25-037-04
https://nvd.nist.gov/vuln/detail/CVE-2025-0994
https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-05-docx/0?