¡¾Îó²îͨ¸æ¡¿Trimble Cityworks·´ÐòÁл¯Îó²î(CVE-2025-0994)

Ðû²¼Ê±¼ä 2025-02-11

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Trimble Cityworks·´ÐòÁл¯Îó²î

CVE   ID

CVE-2025-0994

Îó²îÀàÐÍ

·´ÐòÁл¯

·¢Ã÷ʱ¼ä

2025-02-11

Îó²îÆÀ·Ö

8.6

Îó²îÆ·¼¶

¸ßΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Trimble CityworksÊÇÒ»¿î»ùÓÚµØÀíÐÅϢϵͳ£¨GIS£©µÄ×ʲúÖÎÀíÆ½Ì¨£¬£¬£¬ £¬£¬£¬×¨Îª¹«¹²ÉèÊ©ÖÎÀí¡¢¶¼»áÍýÏëºÍ»ù´¡Éèʩά»¤Éè¼Æ¡£¡£ ¡£¡£ËüÌṩÖÜÈ«µÄ½â¾ö¼Æ»®£¬£¬£¬ £¬£¬£¬×ÊÖúÕþ¸®ºÍÆóÒµÓÐÓÃÖÎÀí×ʲú¡¢Î¬»¤ÉèÊ©¡¢ÓÅ»¯ÊÂÇéÁ÷³Ì£¬£¬£¬ £¬£¬£¬²¢ÌáÉýÔËӪЧÂÊ¡£¡£ ¡£¡£Í¨¹ýÓëGISÊÖÒյɣ¬£¬£¬ £¬£¬£¬CityworksÄܹ»ÊµÏÖ׼ȷµÄ¿Õ¼äÊý¾ÝÖÎÀí£¬£¬£¬ £¬£¬£¬Ö§³ÖÖÇÄܾöæÅºÍ×ÊÔ´·ÖÅÉ¡£¡£ ¡£¡£


2025Äê2ÔÂ11ÈÕ£¬£¬£¬ £¬£¬£¬c7c7ÓéÀÖÆ½Ì¨¼¯ÍÅVSRC¼à²âµ½TrimbleÐû²¼µÄCityworks°²ÅÅÏà¹ØÇ徲ͨ¸æ¡£¡£ ¡£¡£Í¨¸æÏÔʾ£¬£¬£¬ £¬£¬£¬Cityworks 15.8.9֮ǰµÄ°æ±¾¼°Cityworks with Office Companion 23.10֮ǰµÄ°æ±¾±£´æ¸ßΣ·´ÐòÁл¯Îó²î£¨CVE-2025-0994£©¡£¡£ ¡£¡£¸ÃÎó²îÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔÚ¿Í»§µÄMicrosoft Internet Information Services£¨IIS£©Ð§ÀÍÆ÷ÉÏÖ´ÐÐÔ¶³Ì´úÂ루RCE£©£¬£¬£¬ £¬£¬£¬¿ÉÄܵ¼ÖÂϵͳ±»¿ØÖƲ¢Î£¼°Êý¾ÝÇå¾²¡£¡£ ¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Cityworks < 15.8.9
Cityworks with Office Companion < 23.10


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


Éý¼¶ÖÁCityworks 15.8.9»ò¸üа汾
Éý¼¶ÖÁCityworks with Office Companion 23.10»ò¸üа汾


ÏÂÔØÁ´½Ó£º

https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?


3.2 ÔÝʱ²½·¥


¼ì²éIISЧÀÍÆ÷ȨÏÞ£¬£¬£¬ £¬£¬£¬×èֹʹÓÃÍâµØ»òÓò¼¶ÖÎÀíԱȨÏÞ¡£¡£ ¡£¡£

ÓÅ»¯¸½¼þĿ¼ÉèÖ㬣¬£¬ £¬£¬£¬½öÔÊÐí´æ´¢¸½¼þÎļþ¡£¡£ ¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£ ¡£¡£¬£¬£¬ £¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬ £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£ ¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£ ¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£ ¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£ ¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£ ¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://www.cisa.gov/news-events/ics-advisories/icsa-25-037-04
https://nvd.nist.gov/vuln/detail/CVE-2025-0994
https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-05-docx/0?