← Vulnerability feed

Vulnerability record · CVE-2025-59374 · published 17 December 2025

CVE-2025-59374: ASUS Live Update client supply chain compromise with embedded malicious code

Asus · Live Update

Certain builds of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions, but only devices that met those conditions and installed the compromised versions were affected. The product reached End-of-Support in October 2021 and no currently supported devices or products are affected.

9.3 CVSS 4.0 Critical CISA KEV since 17 Dec 2025 EPSS 1.2% · top 33.1% CWE-506 · CWE-506
9.3CVSS 4.0 base score
1.2%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
25 Sep 2026Last modified by NVD

Description

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is a supply chain compromise with a critical CVSS score and KEV listing, but it affects only an End-of-Support client and the record gives no detail on the specific unintended actions.

What it is

Certain builds of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions, but only devices that met those conditions and installed the compromised versions were affected. The product reached End-of-Support in October 2021 and no currently supported devices or products are affected.

Impact

An attacker who controlled the modified update builds could cause targeted devices to perform unintended actions under conditions the record does not specify. The exact actions and resulting level of control are not described in the available data.

Attack surface

The flaw is reached through the Live Update client's update distribution channel, meaning a compromised build is delivered to the endpoint rather than triggered by a remote request. The CVSS 4.0 vector shows network attack vector with no privileges or user interaction required, but the description ties impact to devices meeting specific targeting conditions.

Exploitation

CVE-2025-59374 is listed in CISA KEV with a due date of 2026-01-07, indicating known exploitation, while EPSS is low at 0.01197 (66th percentile). CISA does not list it as used in known ransomware campaigns.

What to do

  • Remove or discontinue the End-of-Support ASUS Live Update client, since no supported fix exists for an EOS product.
  • Follow the vendor advisory and CISA required actions, including applicable BOD 22-01 guidance for cloud services.
  • Inventory endpoints for the ASUS Live Update client and identify any that installed builds from the affected distribution window.
  • Where the client cannot be removed, block its update traffic and restrict outbound connections to vendor update infrastructure.
  • Treat any device that ran a compromised build as potentially untrusted and rebuild it from known-good media.

Detection

  • Hunt for the ASUS Live Update client installed on endpoints, especially versions predating the October 2021 EOS date.
  • Monitor for unexpected process execution or network connections originating from the Live Update client or its install directory.
  • Review update logs and file hashes for Live Update binaries against known-good vendor builds.
  • Alert on outbound traffic to ASUS update endpoints from devices that should no longer run the EOS client.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-59374 to the Known Exploited Vulnerabilities catalog on 17 December 2025 as "ASUS Live Update Embedded Malicious Code Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 7 January 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59374 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-8398DAEMON Tools Lite installers trojanized via supply chain compromiseAttackers breached AVB Disc Soft's build or distribution infrastructure and trojanized three signed binaries (DTHelper.exe, DiscSoftBusServiceLite.ex…KEVEPSS 0.96%analysed9.3CVE-2026-48027Nx Console VS Code extension shipped with embedded malicious codeA malicious version of the Nx Console extension, 18.95.0, was published to the Visual Studio Marketplace and OpenVSX and remained downloadable for ro…KEVEPSS 1.3%analysed9.6CVE-2026-45321TanStack npm packages published with credential-stealing malware via CI/CD chainEighty-four malicious versions across 42 @tanstack/* npm packages were published on 2026-05-11 using the legitimate GitHub Actions OIDC trusted-publi…KEVEPSS 1.1%analysed9.4CVE-2026-33634Trivy and trivy-action supply chain compromise via malicious release and tagsA threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-acti…KEVEPSS 1.7%analysed7.5CVE-2025-54313eslint-config-prettier npm package ships malicious install scriptVersions 8.10.1, 9.1.1, 10.1.6 and 10.1.7 of eslint-config-prettier contain embedded malicious code: installing the package runs an install.js that l…KEVEPSS 4.5%analysed8.6CVE-2025-30154reviewdog/action-setup GitHub Action leaks secrets to workflow logsreviewdog/action-setup@v1 was compromised on March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets into G…KEVEPSS 2.4%analysed8.6CVE-2025-30066tj-actions/changed-files GitHub Action leaks secrets via modified tagsThe tj-actions/changed-files GitHub Action was compromised: tags v1 through v45.0.7 were modified on 2025-03-14 and 2025-03-15 to point at commit 0e5…KEVEPSS 72%analysed8.7CVE-2024-4978JAVS Viewer installer ships backdoored binary with forged signatureThe Justice AV Solutions Viewer Setup 8.3.7.250-1 installer contains an embedded malicious binary signed with an unexpected Authenticode signature, m…KEVEPSS 27%analysed

Source: NIST National Vulnerability Database (record CVE-2025-59374), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.