← All CVEs

CVE-2025-24990

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added 2025-10-14Remediation due 2025-11-04

Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumulative update. Fax modem hardware dependent on this specific driver will no longer work on Windows. Microsoft recommends removing any existing dependencies on this hardware.

7.8
CVSS
6.4%
EPSS (exploit prob.)
93rd
EPSS percentile
2025-10-14
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-822

Affected products

VendorProductAffected versions
microsoftwindows_10_1507< 10.0.10240.21161
microsoftwindows_10_1607< 10.0.14393.8519
microsoftwindows_10_1809< 10.0.17763.7919
microsoftwindows_10_21h2< 10.0.19044.6456
microsoftwindows_10_22h2< 10.0.19045.6456
microsoftwindows_11_22h2< 10.0.22621.6060
microsoftwindows_11_23h2<= 10.0.22631.6060
microsoftwindows_11_24h2< 10.0.26100.6899
microsoftwindows_11_25h2< 10.0.26200.6899
microsoftwindows_server_2008all versions
microsoftwindows_server_2008r2
microsoftwindows_server_2012all versions
microsoftwindows_server_2012r2
microsoftwindows_server_2016<= 10.0.14393.8519
microsoftwindows_server_2019< 10.0.17763.7919
microsoftwindows_server_2022< 10.0.20348.4294
microsoftwindows_server_2022_23h2< 10.0.25398.1913
microsoftwindows_server_2025<= 10.0.26100.6899

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-24990