CVE-2025-59374: ASUS Live Update Embedded Malicious Code Vulnerability
ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause…
How it works
The weakness is categorized as CWE-506, embedded malicious code. Attackers inserted the code into official distribution channels so that the compromised client performed actions chosen by the adversary once installed on targeted systems. Because the modification occurred upstream, standard signature checks on the delivered binary would not have flagged the change.
Am I affected? How to find it in your systems
- Locate installations of ASUS Live Update on Windows endpoints, particularly those paired with ASUS hardware that rely on the utility for driver or firmware updates.
- Inventory systems through endpoint management tools or by querying the installed-programs list and scheduled tasks for any ASUS update component.
- Compare discovered instances against the vendor advisory to determine whether the build in use matches a compromised release; note that the product may already be marked end-of-life or end-of-service.
- Review application and system logs for unexpected outbound connections or process launches initiated by the update client, as these can indicate post-installation behavior consistent with the described supply-chain modification.
How to remediate
Apply mitigations exactly as stated in the vendor advisory. If the advisory indicates the product has reached end-of-life or end-of-service, discontinue its use rather than attempting to update. Remove the client through standard uninstall procedures and verify that no residual scheduled tasks or services remain. Follow any applicable BOD 22-01 guidance for cloud-connected services that may have interacted with the utility.
If you can't patch immediately
- Isolate systems still running the client on network segments that limit outbound access and prevent lateral movement.
- Disable or block execution of the ASUS Live Update binary via application control policies until removal can be completed.
- Increase monitoring of endpoints for anomalous behavior originating from the update process, including unexpected network activity or child processes.
- Plan migration to supported update mechanisms or hardware vendors that continue to receive security maintenance.
If your data may have been exposed
Supply-chain compromises of this type have led to unauthorized access and data exposure in other incidents. Organizations can run a free exposure scan of their domains and email addresses against known breach datasets to determine whether any credentials or identifiers have already appeared in public records.
AICompiled with AI assistance from public sources and published under our editorial standards.