CVE-2026-16172: Netskope Endpoint DLP Service Out-of-Bounds Read Leading to Process Crash
Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver handler. Successful exploitation could potentially crash the EPDLP service, temporarily interrupting DLP enforcement. A successful exploit could potentially also reveal per-boot memory layout information to unauthorized users.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A local standard user on a system running the affected Endpoint DLP service could potentially exploit it. The issue is not described as remotely exploitable.
What does an attacker need to do?
The attacker would need to send a specially crafted message to the Endpoint DLP service that bypasses proper bounds validation. Successful exploitation may crash the kernel driver handler.
What is the likely operational impact?
Exploitation could crash the EPDLP service and temporarily interrupt DLP enforcement. It could also potentially disclose per-boot memory layout information to an unauthorized local user.