CRITICAL

CVE-2025-59374

Asus Live Update 2025-12-17 CVSS v3.1
CVSS
9.8
KEV

Description

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.

Summary dbcve.org

This is a supply chain compromise where unauthorized modifications were introduced into ASUS Live Update client builds. The modified builds were designed to perform unintended actions on devices meeting specific targeting conditions. This affected only devices that both met the targeting criteria AND installed the compromised versions.

Mitigation

Since the Live Update client reached End-of-Support in October 2021 and no currently supported devices are affected, organizations should identify and remove any remaining instances of the legacy ASUS Live Update client from their environments.

Weakness (CWE)

CWE-506

EPSS Score

1.2%
Probability of exploitation in next 30 days
66.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE