CVE-2026-16172

MEDIUM CVSS 4.0: 6.0 EPSS 0.11%
Updated Sep 11, 2026
Netskope
Parameter Value
CVSS 6.0 (MEDIUM)
Type CWE-125 (Out-of-bounds Read)
Vendor Netskope
Public PoC No

Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver handler. Successful exploitation could potentially crash the EPDLP service, temporarily interrupting DLP enforcement.

A successful exploit could potentially also reveal per-boot memory layout information to unauthorized users.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products

netskope:endpoint dlp