• News/
  • https://www.bleepingcomputer.com/news/security/not-all-cisa-linked-alerts-are-urgent-asus-live-update-cve-2025-59374/

Not all CISA-linked alerts are urgent: ASUS Live Update CVE-2025-59374

BleepingComputer
·
Ax Sharma
·
Published Dec 22, 2025
·
Updated

An ASUS Live Update vulnerability tracked as CVE-2025-59374 has been making the rounds in infosec feeds, with some headlines implying recent or ongoing exploitation. The CVE documents a historic supply-chain attack in an End-of-Life (EoL) software product, not a newly emerging threat. Recent coverage of CVE-2025-59374 has framed the issue as a newly relevant security risk following its addition to CISA's Known Exploited Vulnerabilities (KEV) catalog. A closer look, however, shows the reality is much more nuanced. The CVE documents the 2018-2019 "ShadowHammer" supply-chain attack, in which maliciously modified ASUS Live Update binaries were selectively delivered to a small number of targeted systems. The CVE entry for the compromise, now-rated a 9.3 (Critical) on the CVSS scale, states: "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue. The 'unsupported when assigned' text already suggests that the CVE was filed for an EoL product. The primary vendor advisory linked to in the CVE entry is from 2019. This ad...

Read full article

Affected Software

1 affected component
ASUS Live Update

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the ASUS Live Update vulnerability CVE-2025-59374 and clarifies misconceptions about its urgency.

2

What security implications are discussed in relation to ASUS Live Update?

The article highlights a supply-chain attack associated with ASUS Live Update that could potentially compromise system security.

3

What products or software are affected by the vulnerability CVE-2025-59374?

The affected software is ASUS Live Update, which is used for updating ASUS device software.

4

Is the CVE-2025-59374 vulnerability currently being exploited?

The article suggests that there are misleading implications about ongoing exploitation of this vulnerability.

5

What does CISA's involvement indicate regarding the CVE-2025-59374 vulnerability?

CISA's involvement indicates that the vulnerability has been recognized as significant but not necessarily urgent.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203