CISA Adds ASUS Embedded Malicious Code Vulnerability to KEV List Following Active Exploitation
The Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability related to ASUS Live Update to its Known Exploited Vulnerabilities (KEV) catalog, indicating a significant risk for affected systems.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability related to ASUS Live Update to its Known Exploited Vulnerabilities (KEV) catalog, indicating a significant risk for affected systems.
The vulnerability, identified as CVE-2025-59374, affects ASUS Live Update, a utility used for distributing firmware and software updates to ASUS devices. The vulnerability arises from embedded malicious code inserted through a supply chain compromise, potentially leading devices to execute unintended actions.
Attribute Details
CVE ID CVE-2025-59374
Affected Product ASUS Live Update
Vulnerability Type Embedded Malicious Code
The vulnerability, identified as CVE-2025-59374, affects ASUS Live Update, a utility used for distributing firmware and software updates to ASUS devices.
Related CWE CWE-506
Attack Vector Supply Chain Compromise
Impact Unintended device actions, potential malware deployment
Product Status End-of-Life (EoL) / End-of-Service (EoS)
The compromised ASUS Live Update clients may allow attackers to gain control of affected systems, deploy malware, or further compromise environments. The targeting logic remains undisclosed, but the presence of specific conditions suggests a sophisticated attack.
CISA has highlighted that the product may already be End-of-Life (EoL) or End-of-Service (EoS), which reduces the likelihood of receiving future security updates. Therefore, discontinuing the use of the product is advised if mitigations are not viable.
U.S. federal civilian agencies are mandated to apply vendor mitigations or discontinue use by January 7, 2026. Other organizations are strongly advised to follow this guidance. Security teams should evaluate their environments for affected ASUS Live Update deployments and implement available fixes or remove the software if necessary.
CISA's inclusion of CVE-2025-59374 in the KEV catalog indicates active exploitation in the field. Immediate action is recommended to mitigate potential risks associated with this vulnerability.
Based on reporting by Cyber Security News.
