{"id":"CVE-2026-15710","title":"An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141","summary":"An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N","cwe":["CWE-908"],"vendor":"Netskope","product":"Endpoint DLP","affected":["endpoint_dlp < R141"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:31:11.370","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15710","references":[{"url":"https://www.netskope.com/resources/netskope-resources/netskope-security-advisory-nskpsa-2026-006","label":"psirt@netskope.com"}],"tags":["nvd","cve.org"],"epss":0.00104,"epssPercentile":0.01159,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-11T14:52:03.930648Z"},"cvssSource":"cna","ingestedAt":"2026-09-11T16:45:47.861Z","slug":"CVE-2026-15710","body":"## Overview\n\nAn information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper token-based message validation, allowing local unprivileged processes to send unauthorized queries. Additionally, a reply buffer used by the port message handler was not properly initialized before returning data, leaking residual kernel pool memory from prior allocations. A local unprivileged attacker could exploit this vulnerability to enumerate DLP configuration and feature flags, extract live session tokens, and read kernel memory fragments from other users' operations.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}