Junglewise Threat Intelligence

CVE-2026-16172: Netskope Client out-of-bounds heap read in Endpoint DLP

CVE-2026-16172 · Severity: info · Published 2026-09-10

Executive brief

Netskope Client is a security agent that enforces data loss prevention (DLP) policies on endpoints. A local attacker can send a specially crafted message that bypasses validation checks, potentially crashing the DLP service and temporarily disabling data protection controls. The vulnerability may also leak memory layout information that could be used in follow-up attacks.

Technical details

This vulnerability is an out-of-bounds heap read in the Endpoint DLP (EPDLP) service of Netskope Client, stemming from insufficient bounds checking on specially crafted messages sent to the kernel driver handler. A local standard user (no elevated privileges required) can trigger the vulnerability by sending a malformed message. Successful exploitation can crash the EPDLP service, temporarily disrupting DLP policy enforcement, and may disclose per-boot memory layout information that could aid in subsequent exploitation attempts. No patch or fix availability is specified in the advisory.

Affected products

  • Netskope Client <UNKNOWN>

Timeline

  • 2026-09-10: disclosed

References