← back
CVE-2025-24990

Windows Agere Modem Driver Elevation of Privilege Vulnerability

CVSS 7.8 HIGHEPSS 5.8%● KEVCWE-822
In short

A vulnerability in the Agere Modem driver that comes with Windows allows attackers to gain elevated system privileges. Microsoft has removed this driver and users should stop relying on fax modem hardware that depends on it.

Technical detail

The Agere Modem driver (ltmdm64.sys) contains a privilege escalation vulnerability (CWE-822) that enables local attackers to elevate privileges to system level. The driver has been removed in October cumulative updates; systems still using dependent fax modem hardware are exposed until updated.

Summary generated and translated by AI from the official description.
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →