CVE-2026-16174: Netskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool Overflow
Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption. Successful exploitation would require the EPDLP module to be enabled in the client configuration, and that Memory Integrity is disabled. A successful exploit could potentially result in a denial-of-service, arbitrary code execution, or privilege escalation on the local machine.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Ensure Windows Memory Integrity is enabled. The vulnerability requires that Memory Integrity is disabled for exploitation.
Netskope Endpoint DLP (EPDLP) driver/module Memory Integrity = enabled - Configuration
Disable the EPDLP module in the client configuration if not required. Successful exploitation would require the EPDLP module to be enabled.
Netskope Endpoint DLP (EPDLP) module EPDLP module enabled in client configuration = disabled - Compensating control
If EPDLP is enabled, restrict access to the EPDLP process port so unprivileged users cannot send crafted messages to the port (exploitation involves sending a crafted message to the EPDLP process port).
Event History
Frequently Asked Questions
Which systems are exposed to exploitation?
Exposure is limited to Windows systems running Netskope Endpoint DLP with the EPDLP module enabled in the client configuration and Memory Integrity disabled.
What level of access does an attacker need?
The attacker must already be a privileged local user and be able to send a crafted message to the EPDLP process port. The described attack is local rather than network-based.
What is the impact if exploitation succeeds?
Successful exploitation may cause a denial of service, arbitrary code execution, or privilege escalation on the local machine.