Junglewise Threat Intelligence

CVE-2026-16174: Netskope Endpoint DLP integer overflow on Windows

CVE-2026-16174 · Severity: info · Published 2026-09-10

Executive brief

Netskope Endpoint DLP (EPDLP), a data loss prevention agent for Windows systems, contains an integer overflow vulnerability that allows a local privileged user to send specially crafted messages to the EPDLP process. Exploitation can cause memory corruption, leading to denial of service, unauthorized code execution, or privilege escalation on the affected workstation. Successful attacks require both the EPDLP module to be enabled and Memory Integrity protection to be disabled.

Technical details

The vulnerability is an integer overflow in the Netskope Endpoint DLP process on Windows, triggered by a crafted message sent to the EPDLP process port. The vulnerability class is integer overflow leading to memory corruption. Attack vector is local; exploitation requires a privileged user on the system, EPDLP to be enabled in client configuration, and Memory Integrity protection to be disabled. A successful exploit could result in denial of service, arbitrary code execution, or privilege escalation on the local machine. Patch status and availability have not been detailed in the advisory.

Affected products

  • Netskope Endpoint DLP

Timeline

  • 2026-09-10: disclosed

References