Impact
A kernel pool overflow can arise when an integer overflow is triggered by a crafted message sent to the Netskope Endpoint DLP Driver’s process port. The overflow corrupts memory, potentially allowing a local attacker to cause a denial‑of‑service, execute arbitrary code, or elevate privileges on the host. The flaw fundamentally stems from CWE‑190, an integer overflow that can be abused when input is unchecked.
Affected Systems
The vulnerability targets Windows systems running the Netskope Endpoint DLP client with the EPDLP module enabled. It requires the Windows Memory Integrity (Hypervisor‑Protected Code Integrity) feature to be disabled, and the EPDLP service must be active and listening for messages. Any device that has installed the Netskope client with DLP enabled and Memory Integrity turned off is susceptible.
Risk and Exploitability
The CVSS score of 8.7 marks this as a high‑severity flaw. EPSS is not available and the issue is not listed in KEV, yet the need for a local privileged user to send a crafted message makes the attack vector local. Because Memory Integrity is a defensive technology, turning it off substantially increases the likelihood that the kernel pool overflow will succeed, raising the practical risk for organizations that have not enabled this feature or who have not patched the client.
OpenCVE Enrichment