CVE-2025-24052
7.8Microsoft · Windows
The Agere Modem driver (ltmdm64.sys) in Microsoft Windows contains a stack-based buffer overflow vulnerability, leading to its removal from the operating system.
Executive summary
A critical stack-based buffer overflow vulnerability exists in the third-party Agere Modem driver bundled with multiple versions of Microsoft Windows, necessitating the removal of the driver.
Vulnerability
This is a stack-based buffer overflow (CWE-121) within the ltmdm64.sys Agere Modem driver. The vulnerability requires local, low-privileged access to trigger, which can result in a total impact to confidentiality, integrity, and availability.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high severity level. Successful exploitation allows a local attacker to execute arbitrary code with elevated system privileges, potentially leading to full system compromise, data theft, or complete service disruption.
Because the driver is native to these Windows versions, the attack surface is widespread across enterprise environments. Impacted systems relying on legacy fax modem hardware will lose functionality upon applying the patch, as the driver is being removed entirely to eliminate the risk.
Remediation
Immediate Action: Apply the October 2025 cumulative Windows updates immediately, which removes the vulnerable ltmdm64.sys driver from the system.
Proactive Monitoring: Monitor system logs for unusual driver activity or unexpected crashes associated with modem hardware prior to patching.
Compensating Controls: Ensure that strict local access controls are enforced to prevent unauthorized users from interacting with hardware-level drivers.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations must prioritize the deployment of the October 2025 cumulative security updates to remediate this flaw. While the removal of the driver will disable legacy fax modem hardware, the security risk posed by the buffer overflow necessitates this action. Verify that critical business processes do not rely on this legacy hardware before applying the update to avoid unexpected operational downtime.
More Microsoft CVEs
Sources
- Windows Agere Modem Driver Elevation of Privilege Vulnerability Vendor advisory