CVE-2026-16174: Netskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool Overflow

Published Sep 10, 2026
·
Updated

Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption. Successful exploitation would require the EPDLP module to be enabled in the client configuration, and that Memory Integrity is disabled. A successful exploit could potentially result in a denial-of-service, arbitrary code execution, or privilege escalation on the local machine.

Affected Software

1 affected component
Netskope Netskope Endpoint DLP (EPDLP) Driver

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Ensure Windows Memory Integrity is enabled. The vulnerability requires that Memory Integrity is disabled for exploitation.

    Netskope Endpoint DLP (EPDLP) driver/module Memory Integrity = enabled
  2. Configuration

    Disable the EPDLP module in the client configuration if not required. Successful exploitation would require the EPDLP module to be enabled.

    Netskope Endpoint DLP (EPDLP) module EPDLP module enabled in client configuration = disabled
  3. Compensating control

    If EPDLP is enabled, restrict access to the EPDLP process port so unprivileged users cannot send crafted messages to the port (exploitation involves sending a crafted message to the EPDLP process port).

Event History

Sep 10, 2026
CVE Published
via MITRE·10:51 PM
Data Sourced
via MITRE·10:51 PM
DescriptionWeakness

Frequently Asked Questions

1

Which systems are exposed to exploitation?

Exposure is limited to Windows systems running Netskope Endpoint DLP with the EPDLP module enabled in the client configuration and Memory Integrity disabled.

2

What level of access does an attacker need?

The attacker must already be a privileged local user and be able to send a crafted message to the EPDLP process port. The described attack is local rather than network-based.

3

What is the impact if exploitation succeeds?

Successful exploitation may cause a denial of service, arbitrary code execution, or privilege escalation on the local machine.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203