Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-16172— Netskope Endpoint DLP Service Out-of-Bounds Read Leading to Process Crash

Quick assessment

Affected
Netskope Endpoint DLP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Netskope 已收到关于影响 Netskope 客户端中终端数据防泄漏(EPDLP)服务的堆内存越界读取漏洞的通知。本地标准用户可能发送一条未经过适当边界检查的特殊构造消息,从而导致内核驱动程序处理程序崩溃。成功利用该漏洞可能导致 EPDLP 服务崩溃,暂时中断数据防泄漏(DLP)策略执行。成功利用还可能向未授权用户泄露每次启动时的内存布局信息。

CVSS 6.0 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-16172

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Netskope Endpoint DLP Service Out-of-Bounds Read Leading to Process Crash
Source: CVE Program / CVE List V5
Vulnerability Description
Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver handler. Successful exploitation could potentially crash the EPDLP service, temporarily interrupting DLP enforcement. A successful exploit could potentially also reveal per-boot memory layout information to unauthorized users.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Netskope Endpoint DLP 0 ~ 141.0 -

II. Public POCs for CVE-2026-16172

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16172

登录查看更多情报信息。

Vendor Advisories for CVE-2026-16172 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-16172

No comments yet


Leave a comment