---
id: CVE-2025-59374
title: "\"UNSUPPORTED WHEN ASSIGNED\"\_Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise.\_The modified builds could cause devices meeting specific targeting…"
summary: "\"UNSUPPORTED WHEN ASSIGNED\"\_Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise.\_The modified builds could cause devices meeting specific targeting…"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-506
vendor: asus
product: live_update
affected:
  - live_update < 3.6.8
patched:
  - live_update 3.6.8
published: '2025-12-17'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59374'
references:
  - url: 'https://www.asus.com/news/hqfgvuyz6uyayje1/'
    label: 54bf65a7-a193-42d2-b1ba-8e150d3c35e1
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59374
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
epss: 0.01197
epssPercentile: 0.66798
kev: true
kevDateAdded: '2025-12-17'
kevDueDate: '2026-01-07'
kevRansomware: false
exploited: true
zeroDay: true
ingestedAt: '2026-09-25T23:21:16.945Z'
---

## Overview

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.

## Affected

- `live_update < 3.6.8`

## Remediation

Upgrade past the affected range:

- `live_update 3.6.8`
