Impact
The vulnerability is an out-of-bounds heap read (CWE-125) in the Endpoint DLP (EPDLP) service of the Netskope Client, triggered by improper validation. A local standard user can send a specially crafted message that is not properly bounds‑checked, likely causing the kernel driver handler to crash. Successful exploitation could temporarily interrupt DLP enforcement and potentially reveal per‑boot memory layout information to an unauthorized user.
Affected Systems
Netskope Endpoint DLP service. No specific product versions are listed, so all current releases should be examined for this flaw.
Risk and Exploitability
The CVSS score is 6.0, indicating medium severity. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, meaning no known public exploits to date. The attack vector likely requires local access to the Netskope Client, with a standard user being able to send a specially crafted message to trigger the heap read. Successful exploitation would result in a crash of the enforcement and possibly exposing per‑boot memory layout information to the attacker, but does not provide code execution or privilege escalation.
OpenCVE Enrichment