logo

CISA warns ASUS Live Update backdoor is still exploitable, seven years on

ID: 8735e45d-3842-5665-85e2-401ce84d1933

STIX ID: report--8735e45d-3842-5665-85e2-401ce84d1933

Feed Name: Malwarebytes Blog

Threat Score
85/100

Date Published: 2025-12-19

Date Updated: 2026-04-28

...
...

**ASUS Live Update (CVE-2025-59374) added to CISA KEV:** CISA added a CVSS 9.3 vulnerability in ASUS Live Update to its Known Exploited Vulnerabilities catalog, noting active exploitation; the report recalls a prior 2018 supply-chain compromise—attributed to state-sponsored APTs—that inserted a backdoor into the utility, and provides user remediation steps (update to 3.6.8 or later or reinstall from official ASUS product pages).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.