Executive brief
Netskope Client's Endpoint DLP component on Windows contains a kernel driver vulnerability that allows unprivileged local users to bypass security controls and leak sensitive data. An attacker could read DLP policy configurations, extract active session tokens, and access kernel memory fragments, potentially compromising data protection policies and user session security across an organization.
Technical details
The Endpoint DLP kernel driver (epdlpdrv.sys) fails to validate token-based message integrity on internal communication channels between user-space and kernel components. Additionally, reply buffers in the port message handler are not properly initialized before returning data, causing uninitialized kernel pool memory to leak to unprivileged callers. A local unprivileged attacker can send crafted messages to enumerate DLP configuration, extract live session tokens, and read residual kernel memory. The vulnerability affects all versions prior to R141, and patches are available in the updated release.
Affected products
- Netskope Client prior to R141
Timeline
- 2026-09-11: disclosed