CVE-2025-24990
KEVmassUntrusted Pointer Dereference in Windows Agere Modem Driver (ltmdm64.sys)
CISA: Microsoft Windows Untrusted Pointer Dereference Vulnerability
CVE-2025-24990 is an untrusted pointer dereference (CWE-822) in the third-party Agere modem driver (ltmdm64.sys) that Microsoft ships natively with supported Windows client and server operating systems. Exploitation requires local access with limited privileges, and successful attacks yield high impact to the system's confidentiality, integrity, and availability (CVSS 3.1 7.8), a scoring pattern consistent with local privilege escalation. Because the driver is present by default, every supported Windows 10 build, Windows 11 build, and Windows Server 2008/2012/2016 installation listed by Microsoft is affected until patched. The flaw is being actively exploited in the wild — it was added to CISA's KEV on 2025-10-14 — although no public proof-of-concept is known. Microsoft remediated it in the October 2025 cumulative updates by removing ltmdm64.sys entirely, which means fax modem hardware that depends on this driver will stop working after patching.
What to do: Apply the October 2025 (or later) Windows cumulative update, which remediates the flaw by removing ltmdm64.sys, and prioritize systems where untrusted or low-privileged users can run code (RDS/VDI hosts, shared workstations, jump servers). After patching, check for Agere-based fax modem dependencies tied to ltmdm64.sys, as that hardware will no longer function and will need replacement or an alternative. Federal agencies must apply mitigations per vendor instructions or follow BOD 22-01 timelines for cloud services.
| Microsoft Windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 22H2, 23H2, 24H2, 25H2 |
| Microsoft Windows Server | 2008, 2012, 2016 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2008, windows server 2012, windows server 2016
- Weakness
- CWE-822
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H