Supply Chain Vulnerability in ASUS Live Update Client Affects Specific Devices
CVE-2025-59374

9.3CRITICAL

Key Information:

Vendor

Asus

Vendor
CVE Published:
17 December 2025

What is CVE-2025-59374?

The ASUS Live Update client experienced a significant vulnerability due to unauthorized modifications resulting from a supply chain compromise. Certain versions of the software were altered and distributed, leading to unintended actions on devices that met specific targeting conditions. Since these compromised versions are from a product that reached End-of-Support (EOS) in October 2021, only devices with these specific versions installed are affected. Users are urged to uninstall these outdated versions to safeguard their devices.

Affected Version(s)

live update before 3.6.6

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59374 : Supply Chain Vulnerability in ASUS Live Update Client Affects Specific Devices