Out-of-Bounds Heap Read Vulnerability in Netskope Client Endpoint DLP
CVE-2026-16172
6MEDIUM
What is CVE-2026-16172?
Netskope has identified an out-of-bounds heap read vulnerability in the Endpoint DLP service of the Netskope Client. This issue arises from insufficient validation of specially crafted messages sent by a local standard user, which could lead to a crash of the kernel driver handler. Exploiting this vulnerability may disrupt DLP enforcement functionalities temporarily and may expose unauthorized users to per-boot memory layout information. It is crucial for users to remain vigilant and apply recommended security measures.
Affected Version(s)
Endpoint DLP Windows 0 < 141.0
