LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-59374: ASUS Live Update Embedded Malicious Code Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 17, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 7, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-59374 to its Known Exploited Vulnerabilities catalog on Dec 17, 2025, with a federal patch deadline of Jan 7, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause…

ASUS Live Update was distributed with unauthorized modifications from a supply chain compromise. The affected clients contained embedded malicious code that could trigger unintended actions on devices meeting specific targeting conditions. The product may be end-of-life or end-of-service, which increases long-term exposure for organizations still running it.

How it works

The weakness is categorized as CWE-506, embedded malicious code. Attackers inserted the code into official distribution channels so that the compromised client performed actions chosen by the adversary once installed on targeted systems. Because the modification occurred upstream, standard signature checks on the delivered binary would not have flagged the change.

Am I affected? How to find it in your systems

How to remediate

Apply mitigations exactly as stated in the vendor advisory. If the advisory indicates the product has reached end-of-life or end-of-service, discontinue its use rather than attempting to update. Remove the client through standard uninstall procedures and verify that no residual scheduled tasks or services remain. Follow any applicable BOD 22-01 guidance for cloud-connected services that may have interacted with the utility.

If you can't patch immediately

If your data may have been exposed

Supply-chain compromises of this type have led to unauthorized access and data exposure in other incidents. Organizations can run a free exposure scan of their domains and email addresses against known breach datasets to determine whether any credentials or identifiers have already appeared in public records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedASUS · Live Update
WeaknessCWE-506
Added to CISA KEVDec 17, 2025
Federal patch deadlineJan 7, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities