TROYANOSYVIRUS
Back to CVEs

CVE-2025-24990

HIGHCISA KEV
7.8

Description

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware.

CVE Details

CVSS v3.1 Score7.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published10/14/2025
Last Modified11/18/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorMicrosoft
ProductWindows
Vulnerability NameMicrosoft Windows Untrusted Pointer Dereference Vulnerability
KEV Date Added2025-10-14
Remediation Due Date2025-11-04
Ransomware UseUnknown

Affected Products

microsoft:windows_10_1507microsoft:windows_10_1607microsoft:windows_10_1809microsoft:windows_10_21h2microsoft:windows_10_22h2microsoft:windows_11_22h2microsoft:windows_11_23h2microsoft:windows_11_24h2microsoft:windows_11_25h2microsoft:windows_server_2008microsoft:windows_server_2012microsoft:windows_server_2016microsoft:windows_server_2019microsoft:windows_server_2022microsoft:windows_server_2022_23h2microsoft:windows_server_2025

Weaknesses (CWE)

CWE-822

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.