Vulnerability record · CVE-2025-59374 · published 17 December 2025
CVE-2025-59374: ASUS Live Update client supply chain compromise with embedded malicious code
Asus · Live Update
Certain builds of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions, but only devices that met those conditions and installed the compromised versions were affected. The product reached End-of-Support in October 2021 and no currently supported devices or products are affected.
Description
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
high priorityThe flaw is a supply chain compromise with a critical CVSS score and KEV listing, but it affects only an End-of-Support client and the record gives no detail on the specific unintended actions.
What it is
Certain builds of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions, but only devices that met those conditions and installed the compromised versions were affected. The product reached End-of-Support in October 2021 and no currently supported devices or products are affected.
Impact
An attacker who controlled the modified update builds could cause targeted devices to perform unintended actions under conditions the record does not specify. The exact actions and resulting level of control are not described in the available data.
Attack surface
The flaw is reached through the Live Update client's update distribution channel, meaning a compromised build is delivered to the endpoint rather than triggered by a remote request. The CVSS 4.0 vector shows network attack vector with no privileges or user interaction required, but the description ties impact to devices meeting specific targeting conditions.
Exploitation
CVE-2025-59374 is listed in CISA KEV with a due date of 2026-01-07, indicating known exploitation, while EPSS is low at 0.01197 (66th percentile). CISA does not list it as used in known ransomware campaigns.
What to do
- Remove or discontinue the End-of-Support ASUS Live Update client, since no supported fix exists for an EOS product.
- Follow the vendor advisory and CISA required actions, including applicable BOD 22-01 guidance for cloud services.
- Inventory endpoints for the ASUS Live Update client and identify any that installed builds from the affected distribution window.
- Where the client cannot be removed, block its update traffic and restrict outbound connections to vendor update infrastructure.
- Treat any device that ran a compromised build as potentially untrusted and rebuild it from known-good media.
Detection
- Hunt for the ASUS Live Update client installed on endpoints, especially versions predating the October 2021 EOS date.
- Monitor for unexpected process execution or network connections originating from the Live Update client or its install directory.
- Review update logs and file hashes for Live Update binaries against known-good vendor builds.
- Alert on outbound traffic to ASUS update endpoints from devices that should no longer run the EOS client.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-59374 to the Known Exploited Vulnerabilities catalog on 17 December 2025 as "ASUS Live Update Embedded Malicious Code Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 7 January 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.asus.com/news/hqfgvuyz6uyayje1/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59374 | US Government Resource |
Track CVE-2025-59374 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-59374), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.