LiveActive security incident?Get immediate response
CVE Record

CVE-2025-59374: "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthori...

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.

CriticalCVSS 9.3Known exploitedUpdated
Glexia's TakeHuman reviewedcritical

Security readout for executives and security teams

Plain-English summary

CVE-2025-59374 covers a past supply-chain compromise of certain ASUS Live Update client versions. Unauthorized modifications were distributed and could trigger unintended actions only on specifically targeted devices. ASUS says Live Update reached end-of-support in October 2021 and no currently supported devices or products are affected.

Executive priority

Treat as high priority for legacy asset review, not broad emergency patching. The business concern is trust in historical update software and possible targeted compromise on older devices. Supported ASUS products are reported unaffected, reducing current enterprise-wide urgency.

Technical view

The issue is classified as CWE-506: embedded malicious code. Affected scope is ASUS Live Update before 3.6.6, with default status listed as unaffected outside that scope. CVSS 4.0 score is 9.3 due to network-accessible, unauthenticated, no-user-interaction impact on vulnerable confidentiality, integrity, and availability.

Likely exposure

Exposure is most likely in legacy environments retaining old ASUS Live Update installations before 3.6.6. Current supported ASUS devices or products are stated as unaffected. Risk depends on whether compromised builds were installed and whether device-specific targeting conditions were met.

Exploitation context

The CVE describes a supply-chain compromise with unauthorized modified builds. The provided CISA KEV signal is false, so the bundle does not support claiming current active exploitation. The available evidence indicates targeted impact rather than universal compromise of all installations.

Researcher notes

Evidence is limited to the CVE record, ASUS advisory, and CISA KEV reference in the bundle. Do not infer affected models, indicators, payload behavior, or current exploitation beyond those sources. The key research task is scoping legacy Live Update presence and version history.

Mitigation direction

  • Inventory endpoints for ASUS Live Update and record installed versions.
  • Remove unsupported Live Update installations where business processes allow.
  • Check ASUS advisory for vendor-specific guidance and replacement recommendations.
  • Prioritize legacy systems that installed Live Update before version 3.6.6.
  • Review endpoint security telemetry for unusual behavior on affected legacy devices.

Validation and detection

  • Confirm whether ASUS Live Update is present on managed endpoints.
  • Compare installed versions against the affected range: before 3.6.6.
  • Identify devices that may have received historical Live Update packages.
  • Check whether assets are current supported ASUS products.
  • Review CISA KEV status before asserting active exploitation.
Prepared
Reviewed
Confidence
high
Sources
4

Michael Williams reviewed this cited source version on .

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-506: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-59374 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.3 (4.0)
Known Exploited
Yes
Published

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
3Source links

CISA KEV status

Status
Known exploited
Source
CISA / ADP
Date added
Not provided

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.3CVSS 4.0CriticalCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NPrimary CVE score

Vulnerability scoring details

Base CVSS 4.0 score

9.3Critical
CVSS 4.0 vector shape for CVE-2025-59374Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
ASUSlive updatebefore 3.6.6unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-506 · source CWE mapping

Embedded Malicious Code

Embedded Malicious Code represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.