CVE-2025-59374
ASUS Live Update Embedded Malicious Code Vulnerability
Description
CVE-2025-59374 is a critical supply chain compromise vulnerability (CVSS 9.8) affecting certain versions of the ASUS Live Update client, a utility used by ASUS computers to automatically receive firmware, driver, and software updates. Marked as "unsupported when assigned," this vulnerability involves unauthorized modifications introduced into ASUS Live Update builds through a supply chain attack, causing affected devices meeting specific targeting conditions to perform unintended actions. It is listed in CISA's KEV catalog with a remediation deadline of January 7, 2026, and has an EPSS score of 0.31785 (96.7th percentile). Ransomware association is currently unknown.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorCWEs
Affected Products
| Vendor | Product | Version |
|---|---|---|
| asus | live update | < 3.6.8 |
References
- https://www.asus.com/news/hqfgvuyz6uyayje1/(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59374(US Government Resource)
Weakness Type
CWE-506: Embedded Malicious Code
CWE-506 refers to software that contains code segments designed to perform unauthorized, harmful actions that go against the legitimate user's interests. Unlike typical vulnerabilities that arise from coding errors, CWE-506 indicates intentionally malicious functionality embedded in otherwise legitimate software. In CVE-2025-59374, threat actors compromised the ASUS Live Update supply chain and inserted unauthorized code into the update client builds. This malicious code was designed to execute specific actions on devices meeting certain targeting criteria, effectively turning a trusted system utility into a targeted malware delivery mechanism.
Impact Analysis
The business impact of CVE-2025-59374 is profound because it represents a supply chain compromise — one of the most insidious categories of cybersecurity threats. Confidentiality is fully compromised because the malicious code embedded in the ASUS Live Update client could exfiltrate data, capture credentials, or provide remote access to the affected systems. Integrity is fully compromised since the attacker modified a trusted system utility, meaning any action performed by the compromised update client could alter system configurations, install additional malware, or modify files while appearing to be a legitimate ASUS process. Availability is also fully impacted as the compromised client could disable system functions, corrupt the operating system, or render the device unusable. The supply chain nature of this attack is especially dangerous because users have no reason to distrust updates delivered through ASUS's official update mechanism. The targeting criteria embedded in the malicious builds indicate this was a sophisticated, likely state-sponsored operation designed to compromise specific high-value targets while leaving other systems apparently unaffected to avoid detection. The EPSS score of 0.31785 (96.7th percentile) reflects high exploitation probability, and since the malicious updates were distributed through legitimate channels, traditional network-based defenses would not have prevented the compromise.
Exploit Maturity
CVE-2025-59374 represents a completed supply chain attack rather than a traditional vulnerability with varying exploit maturity. The attack was already executed — compromised builds of ASUS Live Update were distributed through ASUS's legitimate update infrastructure, meaning exploitation occurred transparently to affected users. CISA has added this to the KEV catalog with a remediation deadline of January 7, 2026, confirming the severity and ongoing impact of the compromise. The EPSS score of 0.31785 (96.7th percentile) reflects the high exposure from the supply chain distribution method. ASUS has published a vendor advisory acknowledging the incident. The attack was selective — only devices meeting specific targeting conditions were affected, suggesting a sophisticated threat actor (likely state-sponsored) conducted the supply chain compromise for targeted espionage rather than mass exploitation. Ransomware association is listed as unknown, though the targeting approach suggests the primary motivation was intelligence gathering rather than financial extortion.
Remediation
- Update ASUS Live Update to version 3.6.8 or later — ASUS has released a clean version of the Live Update client that removes the compromised code. Download the update from the official ASUS advisory page or through the ASUS support portal.
- Run the ASUS diagnostic tool — ASUS has provided a diagnostic tool to determine whether your specific system was targeted by the supply chain compromise. Use this tool to assess whether your device met the targeting criteria embedded in the malicious builds.
- Conduct a full system compromise assessment — If the diagnostic tool indicates your system was targeted, treat the device as fully compromised. Perform a forensic investigation, preserve evidence, and consider reimaging the system from known-clean media rather than attempting to clean the existing installation.
- Review all systems with ASUS Live Update installed — Inventory all ASUS systems in your organization and verify which version of Live Update they are running. Prioritize systems that may have been running compromised versions (prior to 3.6.8) during the attack window.
- Implement software supply chain verification — Use this incident as a catalyst to implement binary verification controls such as checking digital signatures, hash verification, and application allowlisting to detect future supply chain compromises affecting update mechanisms from any vendor.
Technical Details
The CVSS v3.1 vector for CVE-2025-59374 is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, yielding a base score of 9.8 (Critical). Attack Vector (Network) reflects that the compromised updates were delivered over the network through ASUS's update infrastructure. Attack Complexity (Low) indicates that no special conditions were needed — the malicious update was delivered through normal update channels. Privileges Required (None) means the attack required no user credentials since the update client runs with system-level privileges. User Interaction (None) means no user action beyond having auto-update enabled was required. Scope (Unchanged) indicates the impact is contained within the affected system's boundary. Confidentiality, Integrity, and Availability are all High, reflecting full system compromise. The attack mechanism involved compromising the ASUS Live Update software supply chain to distribute modified builds that contained embedded malicious code. The compromised versions (prior to 3.6.8) were signed and distributed through ASUS's legitimate update servers, making them indistinguishable from genuine updates to endpoint security tools. The malicious code included targeting logic that checked system characteristics against specific criteria — only devices matching these criteria would have the malicious payload activated. This selective targeting approach is characteristic of advanced persistent threat (APT) operations and was designed to limit the scope of compromise to high-value targets while avoiding widespread detection.
Frequently Asked Questions
What is a supply chain compromise?
A supply chain compromise occurs when an attacker infiltrates the software development or distribution process of a legitimate vendor and inserts malicious code into otherwise trusted software. In this case, ASUS's Live Update client was modified before distribution, causing users to unknowingly install compromised software through the official ASUS update mechanism.
Was every ASUS computer affected?
No, the compromised builds contained targeting logic that only activated the malicious payload on devices meeting specific criteria. Most ASUS devices that received the compromised update were not targeted, but all devices running versions prior to 3.6.8 should still be updated to the clean version.
How can I tell if my device was targeted?
ASUS has released a diagnostic tool that checks whether your specific system matches the targeting criteria used by the compromised builds. Download this tool from the official ASUS advisory page and run it on all ASUS systems in your organization.
Who was behind this supply chain attack?
While the CVE does not attribute the attack to a specific actor, the sophisticated targeting criteria and supply chain compromise technique are consistent with state-sponsored advanced persistent threat (APT) operations. The selective targeting suggests espionage motivations rather than financial gain.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.