HomeSecurityCritical zero-day in Windows Agere Modem actively exploited

Critical zero-day in Windows Agere Modem actively exploited

Microsoft has disclosed two critical zero-day vulnerabilities in the Agere Modem that ships with Windows operating systems, confirming their active exploitation for privilege escalation.

See also: Zero-day exploit in Windows Remote Access Connection Manager

Agere Modem zero-day

The vulnerabilities, tracked as CVE-2025-24990 and CVE-2025-24052 , affect the ltmdm64.sys driver and could allow attackers with low privileges to gain full administrator access. These issues were fixed in the October 2025 cumulative update, but Microsoft warns that affected fax modem hardware will stop working after the update.

The Agere Modem driver, a third-party component natively available in Windows, has long been a dormant risk. The vulnerability, CVE-2025-24990, comes from an untrusted pointer report (CWE-822), allowing attackers to manipulate memory and bypass security boundaries. With a CVSS score of 3.1 7.8, it requires only local access and low privileges, but has a high impact on confidentiality, integrity, and availability.

Microsoft's threat intelligence team, MSTIC, along with researchers from r-tec IT Security and an anonymous contributor, discovered an exploit in the field. The second vulnerability, CVE-2025-24052, involves a stack buffer overflow (CWE-121), with a CVSS score of 7.8. It has been publicly disclosed with a PoC available, but has not yet been seen in active attacks.

See also: Zimbra: Zero-day used to target Brazilian military

Critical zero-day in Windows Agere Modem actively exploited

Both vulnerabilities persist even without active use of the modem, affecting all supported Windows versions from Windows 10 onward. Attackers do not need to interact with the hardware. A simple local exploit is sufficient for privilege escalation. No indicators of compromise (IoCs) are provided in the disclosures, but Microsoft urges checking for the presence of ltmdm64.sys.

These zero-day vulnerabilities highlight the dangers of legacy drivers in modern ecosystems. An attacker with initial access, perhaps through phishing or malware, could load the vulnerable driver and execute code to impersonate administrators. In corporate environments, this escalates to domain control, data exfiltration, or ransomware deployment. Fabian Mosch from r-tec noted that the exploits target driver loading during system startup or service calls, bypassing user-level defenses.

The proof of concept for CVE-2025-24990 involves creating malformed input to the IOCTL , which triggers the reference of a controlled pointer. For CVE-2025-24052, overflow exploits cause stack corruption via buffer overruns in modem emulation routines. The researchers demonstrated privilege escalation from the regular user to the SYSTEM level without a crash.

See also: Hackers exploited Zimbra zero-day with malicious iCalendar files

Critical zero-day in Windows Agere Modem actively exploited

This incident highlights the need for a gradual phasing out of legacy components. Cybersecurity experts recommend endpoint detection rules for abnormal driver loads and regular vulnerability scans. As the exploitation continues, organizations must prioritize these fixes to prevent privilege escalation chains.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS