Information Leakage in Netskope Client for Windows
CVE-2026-15710
What is CVE-2026-15710?
An information leakage vulnerability exists in the Endpoint DLP component of the Netskope Client for Windows, specifically in the epdlpdrv.sys driver before version R141. This issue arises from inadequate token-based message validation on the internal communication channel between the user-space hook DLL and the kernel driver. Consequently, local unprivileged processes can send unauthorized queries, compromising security. Furthermore, a reply buffer managed by the port message handler is improperly initialized, which can lead to the leakage of residual kernel pool memory from prior allocations. This vulnerability may allow an attacker to enumerate DLP configurations and feature flags, extract live session tokens, and read kernel memory fragments related to other users' operations.
Affected Version(s)
Endpoint DLP Windows 0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
