Netskope is notified about a potential gap in its agent (NS Client) in which a malicious actor could trigger a memory leak by sending a crafted DNS packet to a machine. A successful exploitation may require administrative privileges on the machine, based on the exact configuration. A successful exploit can potentially result in user-controllable memory being leaked in a domain name stored on the local machine.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-24662 Netskope is notified about a potential gap in its agent (NS Client) in which a malicious actor could trigger a memory leak by sending a crafted DNS packet to a machine. A successful exploitation may require administrative privileges on the machine, based on the exact configuration. A successful exploit can potentially result in user-controllable memory being leaked in a domain name stored on the local machine.
Fixes

Solution

Upgrade the Netskope Client to version 129.0.0 or newer


Workaround

No workaround given by the vendor.

History

Fri, 15 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Netskope
Netskope netskope
Vendors & Products Netskope
Netskope netskope

Thu, 14 Aug 2025 04:45:00 +0000

Type Values Removed Values Added
Description Netskope is notified about a potential gap in its agent (NS Client) in which a malicious actor could trigger a memory leak by sending a crafted DNS packet to a machine. A successful exploitation may require administrative privileges on the machine, based on the exact configuration. A successful exploit can potentially result in user-controllable memory being leaked in a domain name stored on the local machine.
Title Out-of-Bounds Read Vulnerability in Netskope Client
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Netskope

Published:

Updated: 2025-08-15T12:58:34.161Z

Reserved: 2025-06-09T16:38:39.177Z

Link: CVE-2025-5941

cve-icon Vulnrichment

Updated: 2025-08-15T12:27:54.383Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-14T05:15:26.827

Modified: 2025-08-14T13:11:53.633

Link: CVE-2025-5941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-14T12:59:54Z