CVE-2025-24990: Microsoft Windows Untrusted Pointer Dereference Vulnerability

Published Oct 14, 2025
·
Updated

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware.

Other sources

Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges.

CISA

Windows Agere Modem Driver Elevation of Privilege Vulnerability

Microsoft

Affected Software

45 affected componentsFixes available
Microsoft Windows
Microsoft Windows 10 1507<10.0.10240.21161
Microsoft Windows 10 1607<10.0.14393.8519
Microsoft Windows 10 1809<10.0.17763.7919
Microsoft Windows 10 21h2<10.0.19044.6456
Microsoft Windows 10 22h2<10.0.19045.6456
Microsoft Windows 11 22h2<10.0.22621.6060
Microsoft Windows 11 23h2<=10.0.22631.6060
Microsoft Windows 11 24h2<10.0.26100.6899
Microsoft Windows 11 25h2<10.0.26200.6899
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016<=10.0.14393.8519
Microsoft Windows Server 2019<10.0.17763.7919
Microsoft Windows Server 2022<10.0.20348.4294
Microsoft Windows Server 2022 23h2<10.0.25398.1913
Microsoft Windows Server 2025<=10.0.26100.6899
Microsoft Windows Server 2012<6.2.9200.25722
6.2.9200.25722
Microsoft Windows Server 2012 R2<6.3.9600.22824
6.3.9600.22824
Microsoft Windows Server 2012 R2<6.3.9600.22824
6.3.9600.22824
Microsoft Windows Server 2008<6.0.6003.23571
6.0.6003.23571
Microsoft Windows Server 2008 R2<6.1.7601.27974
6.1.7601.27974
Microsoft Windows 10=1607
10.0.14393.8519
Microsoft Windows Server 2012<6.2.9200.25722
6.2.9200.25722
Microsoft Windows Server 2008 R2<6.1.7601.27974
6.1.7601.27974
Microsoft Windows Server 2008<6.0.6003.23571
6.0.6003.23571
Microsoft Windows Server 2016<10.0.14393.8519
10.0.14393.8519
Microsoft Windows 10<10.0.10240.21161
10.0.10240.21161
Microsoft Windows Server 2016<10.0.14393.8519
10.0.14393.8519
Microsoft Windows Server 2022, 23H2 Edition<10.0.25398.1913
10.0.25398.1913
Microsoft Windows 11=24H2
10.0.26100.6899
Microsoft Windows Server 2025<10.0.26100.6899
10.0.26100.6899
Microsoft Windows 10=21H2
10.0.19044.6456
Microsoft Windows Server 2025<10.0.26100.6899
10.0.26100.6899
Microsoft Windows 11=23H2
10.0.22631.6060
Microsoft Windows 10=22H2
10.0.19045.6456
Microsoft Windows 11=22H2
10.0.22621.6060
Microsoft Windows Server 2022<10.0.20348.4294
10.0.20348.4294
Microsoft Windows Server 2022<10.0.20348.4294
10.0.20348.4294
Microsoft Windows 11=25H2
10.0.26200.6899
Microsoft Windows Server 2019<10.0.17763.7919
10.0.17763.7919
Microsoft Windows Server 2019<10.0.17763.7919
10.0.17763.7919
Microsoft Windows 10=1809
10.0.17763.7919

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.2.9200.25722Patch KB5066875
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.3.9600.22824Patch KB5066873
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.0.6003.23571Patch KB5066877
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.1.7601.27974Patch KB5066876
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.14393.8519Patch KB5066836
  6. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.10240.21161Patch KB5066837
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.25398.1913Patch KB5066780
  8. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.26100.6899Patch KB5066835
  9. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.19044.6456Patch KB5066791
  10. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.22631.6060Patch KB5066793
  11. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.19045.6456Patch KB5066791
  12. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.22621.6060Patch KB5066793
  13. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.20348.4294Patch KB5066782
  14. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.26200.6899Patch KB5066835
  15. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.17763.7919Patch KB5066586
  16. Configuration

    Remove any existing dependencies on the affected fax modem hardware that rely on the Microsoft Windows Agere Modem driver (ltmdm64.sys), as Microsoft recommends removing existing dependencies on this hardware.

    Windows Fax modem hardware / dependencies on Agere Modem driver Dependency on the Microsoft Windows Agere Modem driver (ltmdm64.sys) = remove existing dependencies

Event History

Oct 14, 2025
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-24990?

CVE-2025-24990 has been classified as a critical vulnerability due to the removal of the ltmdm64.sys driver affecting numerous Windows operating systems.

2

How do I fix CVE-2025-24990?

To mitigate CVE-2025-24990, install the latest cumulative updates for your Windows operating system as they address the vulnerability by removing the affected driver.

3

Which versions of Windows are affected by CVE-2025-24990?

CVE-2025-24990 affects various versions of Windows, including Windows Server 2008, 2012, 2016, 2019, and newer Windows 10 and 11 releases.

4

Is there a workaround for CVE-2025-24990 until a patch is applied?

Currently, the recommended approach for CVE-2025-24990 is to promptly update the affected systems, as there are no viable workarounds.

5

What is the impact of CVE-2025-24990 on my system?

The impact of CVE-2025-24990 can potentially lead to system instability and loss of functionality related to fax modems due to the removal of the ltmdm64.sys driver.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203