¡¾Îó²îͨ¸æ¡¿Trimble Cityworks·´ÐòÁл¯Îó²î(CVE-2025-0994)

Ðû²¼Ê±¼ä 2025-02-11

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Trimble Cityworks·´ÐòÁл¯Îó²î

CVE   ID

CVE-2025-0994

Îó²îÀàÐÍ

·´ÐòÁл¯

·¢Ã÷ʱ¼ä

2025-02-11

Îó²îÆÀ·Ö

8.6

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Trimble CityworksÊÇÒ»¿î»ùÓÚµØÀíÐÅϢϵͳ£¨GIS£©µÄ×ʲúÖÎÀíÆ½Ì¨£¬£¬£¬£¬£¬£¬×¨Îª¹«¹²ÉèÊ©ÖÎÀí¡¢¶¼»áÍýÏëºÍ»ù´¡Éèʩά»¤Éè¼Æ ¡£¡£¡£¡£¡£¡£ËüÌṩÖÜÈ«µÄ½â¾ö¼Æ»®£¬£¬£¬£¬£¬£¬×ÊÖúÕþ¸®ºÍÆóÒµÓÐÓÃÖÎÀí×ʲú¡¢Î¬»¤ÉèÊ©¡¢ÓÅ»¯ÊÂÇéÁ÷³Ì£¬£¬£¬£¬£¬£¬²¢ÌáÉýÔËӪЧÂÊ ¡£¡£¡£¡£¡£¡£Í¨¹ýÓëGISÊÖÒյÉ£¬£¬£¬£¬£¬£¬CityworksÄܹ»ÊµÏÖ׼ȷµÄ¿Õ¼äÊý¾ÝÖÎÀí£¬£¬£¬£¬£¬£¬Ö§³ÖÖÇÄܾöæÅºÍ×ÊÔ´·ÖÅÉ ¡£¡£¡£¡£¡£¡£


2025Äê2ÔÂ11ÈÕ£¬£¬£¬£¬£¬£¬¿­Ðý¹ú¼ÊÓÎÏ·¼¯ÍÅVSRC¼à²âµ½TrimbleÐû²¼µÄCityworks°²ÅÅÏà¹ØÇ徲ͨ¸æ ¡£¡£¡£¡£¡£¡£Í¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬Cityworks 15.8.9֮ǰµÄ°æ±¾¼°Cityworks with Office Companion 23.10֮ǰµÄ°æ±¾±£´æ¸ßΣ·´ÐòÁл¯Îó²î£¨CVE-2025-0994£© ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ¿Í»§µÄMicrosoft Internet Information Services£¨IIS£©Ð§ÀÍÆ÷ÉÏÖ´ÐÐÔ¶³Ì´úÂ루RCE£©£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂϵͳ±»¿ØÖƲ¢Î£¼°Êý¾ÝÇå¾² ¡£¡£¡£¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Cityworks < 15.8.9
Cityworks with Office Companion < 23.10


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Éý¼¶ÖÁCityworks 15.8.9»ò¸üа汾
Éý¼¶ÖÁCityworks with Office Companion 23.10»ò¸üа汾


ÏÂÔØÁ´½Ó£º

https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?


3.2 ÔÝʱ²½·¥


¼ì²éIISЧÀÍÆ÷ȨÏÞ£¬£¬£¬£¬£¬£¬×èֹʹÓÃÍâµØ»òÓò¼¶ÖÎÀíԱȨÏÞ ¡£¡£¡£¡£¡£¡£

ÓÅ»¯¸½¼þĿ¼ÉèÖ㬣¬£¬£¬£¬£¬½öÔÊÐí´æ´¢¸½¼þÎļþ ¡£¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ ¡£¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ ¡£¡£¡£¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È ¡£¡£¡£¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐÞ¸Ä ¡£¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://www.cisa.gov/news-events/ics-advisories/icsa-25-037-04
https://nvd.nist.gov/vuln/detail/CVE-2025-0994
https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-05-docx/0?