Security readout for executives and security teams
Plain-English summary
CVE-2025-59374 covers a past supply-chain compromise of certain ASUS Live Update client versions. Unauthorized modifications were distributed and could trigger unintended actions only on specifically targeted devices. ASUS says Live Update reached end-of-support in October 2021 and no currently supported devices or products are affected.
Executive priority
Treat as high priority for legacy asset review, not broad emergency patching. The business concern is trust in historical update software and possible targeted compromise on older devices. Supported ASUS products are reported unaffected, reducing current enterprise-wide urgency.
Technical view
The issue is classified as CWE-506: embedded malicious code. Affected scope is ASUS Live Update before 3.6.6, with default status listed as unaffected outside that scope. CVSS 4.0 score is 9.3 due to network-accessible, unauthenticated, no-user-interaction impact on vulnerable confidentiality, integrity, and availability.
Likely exposure
Exposure is most likely in legacy environments retaining old ASUS Live Update installations before 3.6.6. Current supported ASUS devices or products are stated as unaffected. Risk depends on whether compromised builds were installed and whether device-specific targeting conditions were met.
Exploitation context
The CVE describes a supply-chain compromise with unauthorized modified builds. The provided CISA KEV signal is false, so the bundle does not support claiming current active exploitation. The available evidence indicates targeted impact rather than universal compromise of all installations.
Researcher notes
Evidence is limited to the CVE record, ASUS advisory, and CISA KEV reference in the bundle. Do not infer affected models, indicators, payload behavior, or current exploitation beyond those sources. The key research task is scoping legacy Live Update presence and version history.
Mitigation direction
- Inventory endpoints for ASUS Live Update and record installed versions.
- Remove unsupported Live Update installations where business processes allow.
- Check ASUS advisory for vendor-specific guidance and replacement recommendations.
- Prioritize legacy systems that installed Live Update before version 3.6.6.
- Review endpoint security telemetry for unusual behavior on affected legacy devices.
Validation and detection
- Confirm whether ASUS Live Update is present on managed endpoints.
- Compare installed versions against the affected range: before 3.6.6.
- Identify devices that may have received historical Live Update packages.
- Check whether assets are current supported ASUS products.
- Review CISA KEV status before asserting active exploitation.
Public sources used
Michael Williams reviewed this cited source version on .
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-506: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2025-59374 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Critical
- CVSS
- 9.3 (4.0)
- Known Exploited
- Yes
- Published
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CISA KEV status
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N——Primary CVE scoreVulnerability scoring details
Base CVSS 4.0 score
9.3CriticalVector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source materials
- CVE List V5 sourceCVE List V5
- https://www.asus.com/news/hqfgvuyz6uyayje1/CVE reference · vendor-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59374CVE reference · government-resource
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Embedded Malicious Code
Embedded Malicious Code represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
