LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-24990: Microsoft Windows Untrusted Pointer Dereference Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 14, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 4, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-24990 to its Known Exploited Vulnerabilities catalog on Oct 14, 2025, with a federal patch deadline of Nov 4, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain…

CVE-2025-24990 is an untrusted pointer dereference vulnerability in the Microsoft Windows Agere Modem Driver. Successful exploitation can allow an attacker to escalate privileges and gain administrator rights on the affected system. This matters because privilege escalation flaws in core Windows components can turn limited access into full control, enabling further persistence, lateral movement, or data access if an attacker already has a foothold.

Public detail is limited to the CISA summary and the CWE classification; exact affected builds, attack vectors, and scoring must be confirmed against the Microsoft vendor advisory before acting.

How it works

The weakness is classified as CWE-822 (Untrusted Pointer Dereference). In this class of flaw, software uses a pointer value that an attacker can influence or that originates from an untrusted source without sufficient validation. When the driver later dereferences that pointer, the result can be memory corruption or control-flow hijacking that elevates the attacker's privileges.

According to the CISA summary, the vulnerability resides in the Microsoft Windows Agere Modem Driver and allows privilege escalation to administrator. No further exploit mechanics, preconditions, or code-level details are provided in the available facts, so defenders should treat any public proof-of-concept claims with caution and rely on the vendor advisory for authoritative technical description.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Agere Modem Driver. This driver is typically associated with certain modem hardware and may be present on both client and server installations depending on hardware configuration and installed packages.

How to remediate

The primary remediation is to apply the security update or mitigation instructions issued by Microsoft for CVE-2025-24990. CISA directs organizations to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to an untrusted-pointer privilege-escalation flaw in a Windows driver.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities can lead to full system compromise and subsequent data exposure. Known ransomware use of this specific CVE is not documented in the available facts. If you suspect compromise, isolate affected hosts, preserve forensic evidence, and follow your incident-response process. Separately, you can run a free exposure scan of your email addresses against known breach data to determine whether credentials or personal information have appeared in prior public breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-822
Added to CISA KEVOct 14, 2025
Federal patch deadlineNov 4, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities