CVE-2025-11156: Improper Service Loading Vulnerability in Netskope Endpoint DLP Driver
Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited, a local, authenticated user with Administrator privileges can improperly load the driver as a generic kernel service. This triggers the flaw, causing a system crash (Blue-Screen-of-Death) and resulting in a Denial of Service (DoS) for the affected machine.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11156?
CVE-2025-11156 is categorized as a high-severity vulnerability due to its potential impact on system integrity if exploited.
How do I fix CVE-2025-11156?
To remediate CVE-2025-11156, it is recommended to update the Netskope NS Client to the latest version provided by the vendor.
Can CVE-2025-11156 be exploited remotely?
CVE-2025-11156 cannot be exploited remotely, as it requires local authentication and Administrator privileges.
Who is affected by CVE-2025-11156?
CVE-2025-11156 affects users of the Netskope NS Client running on Windows systems.
What are the potential consequences of CVE-2025-11156?
Exploitation of CVE-2025-11156 can lead to unauthorized access and execution of arbitrary code within the kernel.