Hidden functionality (backdoor) in ASUS Live Update - CVE-2025-59374

 

Hidden functionality (backdoor) in ASUS Live Update - CVE-2025-59374

Published: March 26, 2019 / Updated: December 18, 2025


Vulnerability identifier: #VU18081
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-59374
CWE-ID: CWE-912
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system

The vulnerability exists due to hidden functionality (backdoor) is present in software. A remote attacker can use this functionality to gain full access to the application and compromise the affected system.

Note: this backdoor was implented as a result of ASUS servers compromise within the APT attack dubbed “Operation ShadowHammer”. The campaign ran from June to at least November 2018.


Affected software

ASUS Live Update

How to mitigate CVE-2025-59374

Install a new version of Asus Live Update from vendor's website and use antivirus software to detect and remove potential malware from your computers.


External References

Related Security Bulletins