Citing evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed a significant vulnerability affecting ASUS Live Update to its Known Exploited Vulnerabilities (KEV) database on Wednesday.
The vulnerability, identified as CVE-2025-59374 (CVSS score: 9.3), has been characterized as an embedded malicious code vulnerability that was introduced through a supply chain compromise and may enable attackers to carry out unexpected operations.
A description of the vulnerability released on CVE.org states that some versions of the ASUS Live Update client were issued with unauthorized modifications introduced through a supply chain hack. “Devices that meet certain targeting conditions may behave inadvertently as a result of the updated builds. The hacked versions were only impacted by devices that fulfilled these requirements.
It’s important to note that the vulnerability relates to the supply chain attack read more about CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
