Vulnerability Intelligence Report
ASUS Live Update Embedded Malicious Code Vulnerability
CVE-2025-59374
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.3
CRITICAL
EPSS Probability:1.08%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-506 ↗CWE-506: Embedded Malicious Code
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| ASUS | live update | before 3.6.6 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | ASUSTeK Computer Incorporation · Vendor · Taiwan |
| Reserved | 2025-09-15T01:36:47 |
| Published | 2025-12-17T04:27:06 |
| Last Updated | 2026-02-26T16:07:31 |
Community Chatter & Buzz