CVE-2025-59374
Description
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.
Summary dbcve.org
This is a supply chain compromise where unauthorized modifications were introduced into ASUS Live Update client builds. The modified builds were designed to perform unintended actions on devices meeting specific targeting conditions. This affected only devices that both met the targeting criteria AND installed the compromised versions.
Mitigation
Since the Live Update client reached End-of-Support in October 2021 and no currently supported devices are affected, organizations should identify and remove any remaining instances of the legacy ASUS Live Update client from their environments.