ASUS Live Update < 3.6.8 Embedded Malicious Code (CVE-2025-59374)

high Nessus Plugin ID 298880

Synopsis

The remote Windows host has an application installed which is affected by an embedded malicious code vulnerability.

Description

The version of ASUS Live Update installed on the remote host is prior to 3.6.8 and, therefore, affected by an embedded malicious code vulnerability.

- Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue. (CVE-2025-59374)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to ASUS Live Update version 3.6.8 or later.

See Also

https://www.asus.com/news/hqfgvuyz6uyayje1/

https://www.asus.com/support/FAQ/1018727/

Plugin Details

Severity: High

ID: 298880

File Name: asus_live_update_3_6_8.nasl

Version: 1.1

Type: local

Agent: windows

Family: Windows

Published: 2/12/2026

Updated: 2/12/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: High

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-59374

CVSS v3

Risk Factor: High

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:asus:live_update

Required KB Items: installed_sw/ASUS Live Update, SMB/Registry/Enumerated

Patch Publication Date: 3/26/2019

Vulnerability Publication Date: 12/17/2025

CISA Known Exploited Vulnerability Due Dates: 1/7/2026

Reference Information

CVE: CVE-2025-59374