Supply Chain Vulnerability in ASUS Live Update Client Affects Specific Devices
CVE-2025-59374
9.3CRITICAL
What is CVE-2025-59374?
The ASUS Live Update client experienced a significant vulnerability due to unauthorized modifications resulting from a supply chain compromise. Certain versions of the software were altered and distributed, leading to unintended actions on devices that met specific targeting conditions. Since these compromised versions are from a product that reached End-of-Support (EOS) in October 2021, only devices with these specific versions installed are affected. Users are urged to uninstall these outdated versions to safeguard their devices.
Affected Version(s)
live update before 3.6.6