CVE-2025-59374: ASUS Live Update Embedded Malicious Code Vulnerability
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.
Other sources
ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of the ASUS Live Update client (users should discontinue product utilization). The Live Update client reached End-of-Support in October 2021; if mitigations are unavailable, cease using the product.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Operational
Identify any devices that installed the compromised builds of the ASUS Live Update client and discontinue use of the product on those devices.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59374?
CVE-2025-59374 is considered a critical vulnerability due to its potential impact on device functionality and security.
How do I fix CVE-2025-59374?
To fix CVE-2025-59374, users should update their ASUS Live Update client to the latest version provided by ASUS.
What are the risks associated with CVE-2025-59374?
The risks associated with CVE-2025-59374 include unauthorized access to device functions and potential compromise of sensitive information.
Who is affected by CVE-2025-59374?
Devices running certain modified versions of the ASUS Live Update client are at risk due to this vulnerability.
How did CVE-2025-59374 arise?
CVE-2025-59374 arose from unauthorized modifications introduced through a supply chain compromise affecting the ASUS Live Update client.