"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.asus.com/news/hqfgvuyz6uyayje1/ |
|
History
Wed, 17 Dec 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions and installed the compromised versions were affected. The Live Update client has already reached End-of-Support (EOS) in October 2021, and no currently supported devices or products are affected by this issue. | |
| First Time appeared |
Asus
Asus live Update |
|
| Weaknesses | CWE-506 | |
| CPEs | cpe:2.3:a:asus:live_update:before_3.6.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Asus
Asus live Update |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ASUS
Published:
Updated: 2025-12-17T04:27:06.885Z
Reserved: 2025-09-15T01:36:47.359Z
Link: CVE-2025-59374
No data.
Status : Received
Published: 2025-12-17T05:16:13.080
Modified: 2025-12-17T05:16:13.080
Link: CVE-2025-59374
No data.
OpenCVE Enrichment
No data.