
Last October, Microsoft did something rare: instead of patching a bug, they deleted the driver. CVE-2025-24990 was a kernel EoP in a 56K-modem driver Windows had shipped for two decades — exploited in the wild against an install base of essentially nobody.
Post summary
Microsoft removed the legacy 56k modem driver for CVE-2025-24990 rather than patching it; the kernel elevation‑of‑privilege flaw had been exploited in the wild but only against a negligible install base.
