Executive brief
ASUS Live Update, a utility used to automatically update drivers and firmware on ASUS computers, was compromised in a supply chain attack. Attackers distributed modified versions of the software containing malicious code, allowing them to take control of targeted devices. Because this software reached its end-of-life in 2021, users still running the application should discontinue its use immediately to prevent potential unauthorized access or data loss.
Technical details
This vulnerability is classified as CWE-506 (Embedded Malicious Code) resulting from a supply chain compromise of the ASUS Live Update utility. Unauthorized modifications were introduced into the software builds, which were then distributed to end-users through official channels. When executed, the modified client performs unintended actions on devices that meet specific targeting criteria. The vulnerability has been exploited in the wild. As the product reached End-of-Support (EOS) in October 2021, no official patch is available for the legacy client; users are advised to uninstall the software. Versions prior to 3.6.8 are identified as vulnerable.
Affected products
- ASUS Live Update Versions prior to 3.6.8
Timeline
- 2021-10: other: Product reached End-of-Support (EOS)
- 2025-12-17: disclosed
- 2025-12-17: kev added: Added to CISA KEV catalog
- 2025-12-17: advisory: Vendor advisory published by ASUS