Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited, a local, authenticated user with Administrator privileges can improperly load the driver as a generic kernel service. This triggers the flaw, causing a system crash (Blue-Screen-of-Death) and resulting in a Denial of Service (DoS) for the affected machine.
Advisories

No advisories yet.

Fixes

Solution

Update the Netskope Client to version 132.0.0 or newer


Workaround

EDR solutions can be leveraged to block any process attempting to create a kernel service pointing to epdlpdrv.sys driver.

History

Mon, 01 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Netskope
Netskope netskope
Vendors & Products Microsoft
Microsoft windows
Netskope
Netskope netskope

Fri, 28 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Nov 2025 14:30:00 +0000

Type Values Removed Values Added
Description Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited, a local, authenticated user with Administrator privileges can improperly load the driver as a generic kernel service. This triggers the flaw, causing a system crash (Blue-Screen-of-Death) and resulting in a Denial of Service (DoS) for the affected machine.
Title Improper Service Loading Vulnerability in Netskope Endpoint DLP Driver
Weaknesses CWE-476
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Netskope

Published:

Updated: 2025-11-28T14:35:23.920Z

Reserved: 2025-09-29T14:21:29.625Z

Link: CVE-2025-11156

cve-icon Vulnrichment

Updated: 2025-11-28T14:35:21.431Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-28T15:15:59.900

Modified: 2025-12-01T15:39:33.110

Link: CVE-2025-11156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-01T15:18:32Z