PT-2025-41973 · Microsoft+1 · Windows+1
Published
2025-10-14
·
Updated
2026-05-21
·
CVE-2025-24990
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Agere Modem driver (affected versions not specified)
Description
An untrusted pointer dereference issue exists in the Agere Modem driver
ltmdm64.sys natively shipped with supported Windows operating systems. The flaw occurs because certain IOCTL handlers use METHOD NEITHER and fail to verify whether a pointer is a user-mode or kernel-mode address, allowing arbitrary addresses to be passed into kernel space. This can lead to local privilege escalation to SYSTEM, arbitrary code execution in the kernel, and the bypassing of OS protections and EDR/AV software. Exploitation involves opening a handle to the device via CreateFile(".ltmdm64", ...) and using specially crafted user buffers to achieve arbitrary read and write primitives in the kernel. Real-world exploitation of this issue has been recorded.Recommendations
Remove any existing dependencies on the fax modem hardware dependent on the
ltmdm64.sys driver.
Apply the October cumulative update to remove the ltmdm64.sys driver from the system.Exploit
Fix
LPE
Untrusted Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Agere Modem Driver
Windows