A critical vulnerability, tracked as CVE-2025-59374, was identified in certain versions of the ASUS Live Update client after evidence of active exploitation surfaced. The flaw, which has a CVSS score of 9.3, stems from a supply chain compromise where unauthorized modifications were introduced into the software, allowing attackers to execute unintended actions on targeted devices. The attack, known as Operation ShadowHammer, specifically targeted users based on their network adapters' MAC addresses, with malicious code embedded in trojanized versions of the client distributed between June and November 2018. ASUS addressed the issue in version 3.6.8, and the Live Update client has since reached end-of-support, with the last version being 3.6.15 as of December 2025.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-59374 to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the ongoing risk posed by legacy installations. While the vulnerability only affects devices that installed the compromised versions and met specific targeting conditions, organizations are urged to ensure that unsupported versions of the ASUS Live Update client are removed from their environments. No currently supported ASUS products are affected, but the incident underscores the persistent threat of supply chain attacks and the importance of timely software updates and decommissioning of end-of-life software.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Following the KEV addition, CISA instructed federal civilian agencies to discontinue use of ASUS Live Update by January 7, 2026. Security guidance also urged organizations to remove the unsupported client or update to fixed versions where applicable.
CISA added CVE-2025-59374 to its Known Exploited Vulnerabilities catalog, citing evidence of exploitation and directing attention to the historic ASUS Live Update compromise. The listing elevated the issue for federal defenders despite the software being legacy and unsupported.
CVE-2025-59374 was formally published as a critical supply-chain vulnerability affecting certain ASUS Live Update versions with unauthorized modifications. The entry assigned a CVSS 4.0 score of 9.3 and linked the issue to embedded malicious code.
ASUS Live Update reached end-of-support, leaving the affected client retired and unsupported. Reporting notes that no currently supported ASUS products are impacted by CVE-2025-59374.
ASUS addressed the compromised Live Update issue in version 3.6.8, which removed the affected builds from the update chain. Later reporting notes the vulnerability had been remediated years before its CVE assignment.
Compromised ASUS Live Update clients were distributed between June and November 2018, delivering maliciously modified binaries to targeted systems. More than 600 unique MAC addresses were reportedly embedded in the malware for selective targeting.
An APT group compromised ASUS infrastructure and trojanized ASUS Live Update builds as part of the ShadowHammer supply-chain attack. The malicious software was designed to target specific systems using hard-coded MAC addresses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcemalwarebytes.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.