CVE-2026-16174
largeInteger Overflow in Netskope Endpoint DLP (EPDLP) for Windows
CVE-2026-16174 is an integer overflow (CWE-190) in the Netskope Endpoint DLP (EPDLP) component of the Netskope client on Windows, which corrupts memory when a crafted message is sent to the EPDLP process port. Exploitation requires three conditions: the EPDLP module must be enabled in the Netskope client configuration, Windows Memory Integrity (HVCI) must be disabled on the host, and the sender must be a privileged local user. A successful exploit could yield a denial of service, arbitrary code execution, or local privilege escalation on the affected machine. Only Windows endpoints running the Netskope client with the Endpoint DLP module enabled are affected. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and Netskope (the assigned CNA) has not reported in-the-wild exploitation.
What to do: Check your Netskope client configurations for deployments with the Endpoint DLP (EPDLP) module enabled and identify Windows hosts where Memory Integrity (HVCI) is disabled; enabling Memory Integrity is an effective mitigation. Upgrade the Netskope client to the fixed release per Netskope's advisory (exact fixed version not included in this data), and note that exploitation requires a privileged local user, so limiting local admin rights also reduces risk.
| Netskope Endpoint DLP (EPDLP) module of the Netskope client, on Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption. Successful exploitation would require the EPDLP module to be enabled in the client configuration, and that Memory Integrity is disabled. A successful exploit could potentially result in a denial-of-service, arbitrary code execution, or privilege escalation on the local machine.
- Weakness
- CWE-190
- Vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.