Executive brief
Netskope Endpoint DLP (EPDLP), a data loss prevention agent for Windows systems, contains an integer overflow vulnerability that allows a local privileged user to send specially crafted messages to the EPDLP process. Exploitation can cause memory corruption, leading to denial of service, unauthorized code execution, or privilege escalation on the affected workstation. Successful attacks require both the EPDLP module to be enabled and Memory Integrity protection to be disabled.
Technical details
The vulnerability is an integer overflow in the Netskope Endpoint DLP process on Windows, triggered by a crafted message sent to the EPDLP process port. The vulnerability class is integer overflow leading to memory corruption. Attack vector is local; exploitation requires a privileged user on the system, EPDLP to be enabled in client configuration, and Memory Integrity protection to be disabled. A successful exploit could result in denial of service, arbitrary code execution, or privilege escalation on the local machine. Patch status and availability have not been detailed in the advisory.
Affected products
- Netskope Endpoint DLP
Timeline
- 2026-09-10: disclosed