CVE-2025-59374
KEVmassSupply Chain-Embedded Malicious Code in ASUS Live Update Utility
CISA: ASUS Live Update Embedded Malicious Code Vulnerability
Certain builds of the ASUS Live Update automatic-update client were distributed containing unauthorized code planted through a supply chain compromise (CWE-506, embedded malicious code). The embedded code only caused devices to perform unintended actions when the device met specific attacker-defined targeting conditions and had installed one of the compromised versions, so most installations of the utility were not visibly affected. Where the targeting conditions were met, the malicious code ran with no user privileges required and carried high impact to confidentiality, integrity and availability (CVSS 4.0 score 9.3, critical). The Live Update client reached End-of-Support in October 2021, and ASUS states that no currently supported devices or products are affected, so exposure is limited to legacy systems that installed the compromised builds. CISA added the issue to the Known Exploited Vulnerabilities catalog on 2025-12-17 after evidence of active exploitation; no public proof-of-concept is known and EPSS estimates a 1.2% probability of exploitation in the next 30 days (66th percentile).
What to do: Because Live Update is end-of-support, no patched release exists: inventory legacy ASUS systems that currently or previously ran the client, determine whether compromised builds were installed, and remove or discontinue the utility per the CISA KEV required action (apply vendor mitigations or discontinue use, with BOD 22-01 applying to federal agencies). Check ASUS security advisories for indicators of the compromised versions and hunt on legacy ASUS endpoints for unexpected outbound connections or other signs of the 'unintended actions' described. Supported ASUS products are not affected, so no action is needed on current, in-support devices.
| ASUS Live Update | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.
- Affected
- ASUS Live Update
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- asus
- Products
- live update
- Weakness
- CWE-506
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X