Impact
A kernel-driver information leakage flaw exists in the Netskope Endpoint DLP component when the driver (epdlpdrv.sys) fails to validate messages sent from a user-space hook DLL and returns a reply buffer that is not fully initialized. This defect allows a local unprivileged process to send unauthorized queries and to read residual data from preceding kernel pool allocations. An attacker can consequently enumerate DLP configuration and feature flags, extract live session tokens, and read fragments of kernel memory that belong to other users' operations. The weakness is classified as CWE‑908, indicating improper handling of sensitive data within the system.
Affected Systems
The vulnerability affects Netskope Client for Windows – Endpoint DLP in all released versions prior to R141. The patch package is available by upgrading to version R141 or later. Netskope also recommends applying backported maintenance patch builds R132.0.4.7307, R135.0.2.7298, or R138.0.0.7305 or newer if an upgrade is not possible at the time of installation.
Risk and Exploitability
This flaw carries a CVSS base score of 6.8, representing medium severity, and has no EPSS score available. It is not listed in the CISA KEV catalog. The vulnerability can be exploited only from a local machine by an unprivileged user who can run the Netskope client or load the DLL; there is no known network-basis or remote exploitation vector. An attacker would need to launch the malicious code in the same user session as the Netskope client and use the exposed message pathway to trigger the kernel leak. The most likely attack scenario involves a legitimate user executing malicious code on their own workstation, thereby allowing the attacker to read sensitive configuration and tokens without privilege escalation.
OpenCVE Enrichment