CVE-2025-24990

9.5 CISA KEV

Microsoft · Windows

An untrusted pointer dereference vulnerability exists in the third-party Agere Modem driver (ltmdm64.sys) included with Windows, which allows local attackers to achieve system-level compromise.

Executive summary

A critical untrusted pointer dereference vulnerability in the Agere Modem driver for Windows is confirmed to be under active exploitation in the wild, posing a severe risk to system integrity.

Vulnerability

This flaw involves an untrusted pointer dereference within the Agere Modem driver (ltmdm64.sys). The vulnerability can be triggered by a local attacker with low privileges to execute arbitrary code with elevated system permissions.

Business impact

Successful exploitation of this vulnerability allows an attacker to gain full control over the affected Windows system. Given the CVSS score of 9.5 and the confirmed active exploitation, this represents a critical threat to organizational security, potentially leading to unauthorized data access, malware installation, and total system compromise.

Remediation

Immediate Action: Apply the October cumulative security updates provided by Microsoft, which effectively remove the vulnerable ltmdm64.sys driver from the operating system.

Proactive Monitoring: Monitor system logs for unauthorized attempts to load or interact with legacy modem drivers and track process execution patterns associated with low-privileged accounts.

Compensating Controls: Ensure that endpoint protection solutions are updated and configured to detect and block malicious attempts to exploit driver-level vulnerabilities.

Exploitation status

Public Exploit Available: Yes, multiple public proofs-of-concept are available via GitHub repositories.

Analyst recommendation

Due to the critical nature of this vulnerability and the evidence of active exploitation, immediate patching is required. Administrators must prioritize the deployment of the latest Microsoft cumulative updates to remove the vulnerable driver and neutralize this attack vector across all managed Windows endpoints.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief critical section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Published in the daily brief kev section
  23. Look Back published
  24. Analyst report written
  25. Fix documented version 10.0.10240.21161 per CVE record

Sources