Windows Agere Modem Driver 0-Day Vulnerabilities Actively Exploited To Escalate Privileges
Microsoft has reported two critical zero-day vulnerabilities in the Agere Modem driver included with Windows operating systems. These vulnerabilities have been confirmed to be actively exploited, allowing attackers to escalate privileges.
Microsoft has reported two critical zero-day vulnerabilities in the Agere Modem driver included with Windows operating systems. These vulnerabilities have been confirmed to be actively exploited, allowing attackers to escalate privileges.
The vulnerabilities, identified as CVE-2025-24990 and CVE-2025-24052, affect the ltmdm64.sys driver. They can enable attackers with low privileges to gain full administrator access. These issues were addressed in the October 2025 cumulative update. However, Microsoft has indicated that fax modem hardware reliant on this driver will become non-functional after applying the update.
Vulnerabilities Exposed in Legacy Driver
The Agere Modem driver, a third-party component included in Windows, poses a potential risk. CVE-2025-24990 involves an untrusted pointer dereference (CWE-822), which allows attackers to manipulate memory and breach security boundaries.
This vulnerability has a CVSS 3.1 score of 7.8 and requires only local access and low privileges, but it significantly impacts confidentiality, integrity, and availability.
The second vulnerability, CVE-2025-24052 , is a stack-based buffer overflow (CWE-121), also with a CVSS score of 7.8. Although proof-of-concept code is publicly available, active exploitation has not yet been observed.
Both vulnerabilities affect all supported Windows versions from Windows 10 onward, even without active modem use. A local exploit is sufficient to escalate privileges without hardware interaction.
Microsoft has reported two critical zero-day vulnerabilities in the Agere Modem driver included with Windows operating systems.
CVE ID Description CVSS Score Exploit Status Weakness
CVE-2025-24990 Untrusted Pointer Dereference in ltmdm64.sys 7.8 (Important) Actively Exploited (Functional PoC) CWE-822
CVE-2025-24052 Stack-based Buffer Overflow in ltmdm64.sys 7.8 (Important) Proof-of-Concept Available CWE-121
Microsoft recommends scanning for the presence of ltmdm64.sys. An attacker who gains initial access, potentially through phishing or malware, could exploit these vulnerabilities to gain administrative privileges.
Microsoft's Response and User Guidance
In the October Patch Tuesday release, Microsoft removed ltmdm64.sys, making any dependent Agere modems obsolete. Users relying on this hardware should seek alternatives, as backward compatibility is not available.
Microsoft advises immediate patching and auditing of the driver using tools like Autoruns. For unpatched systems, the driver should be disabled through Device Manager or group policy.
These vulnerabilities emphasize the importance of replacing outdated components. Cybersecurity experts recommend implementing endpoint detection rules for unusual driver loads and conducting regular vulnerability scans. Organizations are urged to prioritize these updates to prevent privilege escalation attacks.
Based on reporting by Cyber Security News.
