Oct 2025: Windows Agere Modem Driver Elevation of Privilege Vulnerability
CVE-2025-24990 Published on October 14, 2025
Windows Agere Modem Driver Elevation of Privilege Vulnerability
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update.
Fax modem hardware dependent on this specific driver will no longer work on Windows.
Microsoft recommends removing any existing dependencies on this hardware.
Known Exploited Vulnerability
This Microsoft Windows Untrusted Pointer Dereference Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges.
The following remediation steps are recommended / required by November 4, 2025: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Weakness Type
Untrusted Pointer Dereference
The program obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Products Associated with CVE-2025-24990
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Windows 10 Version 1507:- Version 10.0.10240.0 and below 10.0.10240.21161 is affected.
- Version 10.0.14393.0 and below 10.0.14393.8519 is affected.
- Version 10.0.17763.0 and below 10.0.17763.7919 is affected.
- Version 10.0.19044.0 and below 10.0.19044.6456 is affected.
- Version 10.0.19045.0 and below 10.0.19045.6456 is affected.
- Version 10.0.22621.0 and below 10.0.22621.6060 is affected.
- Version 10.0.22631.0 and below 10.0.22631.6060 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6899 is affected.
- Version 10.0.26200.0 and below 10.0.26200.6899 is affected.
- Version 6.1.7601.0 and below 6.1.7601.27974 is affected.
- Version 6.1.7601.0 and below 6.1.7601.27974 is affected.
- Version 6.0.6003.0 and below 6.0.6003.23571 is affected.
- Version 6.0.6003.0 and below 6.0.6003.23571 is affected.
- Version 6.2.9200.0 and below 6.2.9200.25722 is affected.
- Version 6.2.9200.0 and below 6.2.9200.25722 is affected.
- Version 6.3.9600.0 and below 6.3.9600.22824 is affected.
- Version 6.3.9600.0 and below 6.3.9600.22824 is affected.
- Version 10.0.14393.0 and below 10.0.14393.8519 is affected.
- Version 10.0.14393.0 and below 10.0.14393.8519 is affected.
- Version 10.0.17763.0 and below 10.0.17763.7919 is affected.
- Version 10.0.17763.0 and below 10.0.17763.7919 is affected.
- Version 10.0.20348.0 and below 10.0.20348.4294 is affected.
- Version 10.0.25398.0 and below 10.0.25398.1913 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6899 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6899 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.