ZeroHour

CVE-2026-16174

large

Integer Overflow in Netskope Endpoint DLP (EPDLP) for Windows

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-16174 is an integer overflow (CWE-190) in the Netskope Endpoint DLP (EPDLP) component of the Netskope client on Windows, which corrupts memory when a crafted message is sent to the EPDLP process port. Exploitation requires three conditions: the EPDLP module must be enabled in the Netskope client configuration, Windows Memory Integrity (HVCI) must be disabled on the host, and the sender must be a privileged local user. A successful exploit could yield a denial of service, arbitrary code execution, or local privilege escalation on the affected machine. Only Windows endpoints running the Netskope client with the Endpoint DLP module enabled are affected. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and Netskope (the assigned CNA) has not reported in-the-wild exploitation.

What to do: Check your Netskope client configurations for deployments with the Endpoint DLP (EPDLP) module enabled and identify Windows hosts where Memory Integrity (HVCI) is disabled; enabling Memory Integrity is an effective mitigation. Upgrade the Netskope client to the fixed release per Netskope's advisory (exact fixed version not included in this data), and note that exploitation requires a privileged local user, so limiting local admin rights also reduces risk.

Affected
Netskope Endpoint DLP (EPDLP) module of the Netskope client, on Windows
Estimated exposure
largeplausibly on the order of 100,000-1,000,000 enterprise Windows endpoints — Netskope's client agent is deployed across thousands of enterprise customers whose endpoint fleets commonly number in the thousands each, but EPDLP is an optional module and the additional requirement that Windows Memory Integrity be…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption. Successful exploitation would require the EPDLP module to be enabled in the client configuration, and that Memory Integrity is disabled. A successful exploit could potentially result in a denial-of-service, arbitrary code execution, or privilege escalation on the local machine.

Weakness
CWE-190
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.