CVE-2025-59374
9.5 CISA KEVASUS · Live Update
ASUS Live Update contains embedded malicious code resulting from a supply chain compromise that allowed for targeted unintended actions on specific devices.
Executive summary
This critical supply chain vulnerability in the ASUS Live Update client has been confirmed as actively exploited in the wild via a sophisticated targeted attack.
Vulnerability
This flaw involves the distribution of unauthorized, modified software builds containing embedded malicious code. The vulnerability allowed attackers to perform unintended actions on devices that met specific targeting criteria, requiring no user interaction or authentication.
Business impact
The exploitation of this vulnerability poses a severe risk of total system compromise, as indicated by the critical CVSS score of 9.5. Successful exploitation allows for unauthorized control over affected hardware, potentially leading to data exfiltration or the installation of further malicious payloads. Given the nature of this supply chain attack, organizations must consider any system that ran the compromised versions as potentially compromised.
Remediation
Immediate Action: Update the software to version 3.6.8 or higher, or discontinue use of the product entirely as the software has reached End of Support.
Proactive Monitoring: Review system logs for unauthorized processes or unexpected network traffic originating from the ASUS Live Update service.
Compensating Controls: Isolate systems running legacy ASUS software from critical segments of the production network until the application can be removed or patched.
Exploitation status
Public Exploit Available: Yes, as documented in technical analysis of the Operation ShadowHammer campaign.
Analyst recommendation
Due to the confirmed active exploitation and the critical severity of this supply chain compromise, immediate action is required. Organizations should prioritize removing the affected ASUS Live Update client from all endpoints. If the software is still in use, ensure it is upgraded to the latest version, though decommissioning the service is the recommended path given its End of Support status.