By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation
Computing

CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation

News Room
Last updated: 2025/12/18 at 1:20 AM
News Room Published 18 December 2025
Share
CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation
SHARE

Dec 18, 2025Ravie LakshmananVulnerability / Software Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting ASUS Live Update to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2025-59374 (CVSS score: 9.3), has been described as an “embedded malicious code vulnerability” introduced by means of a supply chain compromise that could allow attackers to perform unintended actions.

“Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise,” according to a description of the flaw published in CVE.org. “The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected.”

It’s worth noting that the vulnerability refers to the supply chain attack that came to light in March 2019, when ASUS acknowledged that an advanced persistent threat (APT) group managed to breach some of its servers as part of a campaign codenamed Operation ShadowHammer by Kaspersky. The activity is said to have run between June and November 2018.

Cybersecurity

The Russian cybersecurity company said the goal of the attacks was to “surgically target” an unknown pool of users whose machines were identified by their network adapters’ MAC addresses. The trojanized versions of the artifacts came embedded with a hard-coded list of more than 600 unique MAC addresses.

“A small number of devices have been implanted with malicious code through a sophisticated attack on our Live Update servers in an attempt to target a very small and specific user group,” ASUS noted at the time. The issue was fixed in version 3.6.8 of the Live Update software.

The development comes a few weeks after ASUS formally announced that the Live Update client has reached end-of-support (EOS) as of December 4, 2025. The last version is 3.6.15. As a result, CISA has urged Federal Civilian Executive Branch (FCEB) agencies still relying on the tool to discontinue its use by January 7, 2026.

“ASUS is committed to software security and consistently provides real-time updates to help protect and enhance devices,” the company said in a support page. “Automatic, real-time software updates are available via the ASUS Live Update application. Please update the ASUS Live Update to V3.6.8 or higher version to resolve security concerns.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Exynos 2600 specs leak: Will some Galaxy S26 models be miles behind? Exynos 2600 specs leak: Will some Galaxy S26 models be miles behind?
Next Article IT Sustainability Think Tank: What enterprises must do to make sustainability work in 2026 | Computer Weekly IT Sustainability Think Tank: What enterprises must do to make sustainability work in 2026 | Computer Weekly
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Stop Drowning in AI Models: A 3-Pillar Framework for Evaluation | HackerNoon
Stop Drowning in AI Models: A 3-Pillar Framework for Evaluation | HackerNoon
Computing
Why I found microSD Express won’t solve your Nintendo Switch 2 storage problems
Why I found microSD Express won’t solve your Nintendo Switch 2 storage problems
Gadget
AI Is Going To Make Your Next Computer Cost A Lot More, And It’s Pretty Clear Why – BGR
AI Is Going To Make Your Next Computer Cost A Lot More, And It’s Pretty Clear Why – BGR
News
cPanel Web Hosting Recommendations for 2026
cPanel Web Hosting Recommendations for 2026
Gadget

You Might also Like

Stop Drowning in AI Models: A 3-Pillar Framework for Evaluation | HackerNoon
Computing

Stop Drowning in AI Models: A 3-Pillar Framework for Evaluation | HackerNoon

9 Min Read
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
Computing

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

2 Min Read
Blue Origin aims to break the accessibility barrier by launching first wheelchair user into space
Computing

Blue Origin aims to break the accessibility barrier by launching first wheelchair user into space

6 Min Read
Thunderbird Expanding Microsoft Exchange & Protocol Support For 2026
Computing

Thunderbird Expanding Microsoft Exchange & Protocol Support For 2026

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?