{"id":"CVE-2026-16172","title":"Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client","summary":"Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds …","severity":"medium","cvss":6,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:H","cwe":["CWE-125"],"vendor":"Netskope","product":"Endpoint DLP","affected":["endpoint_dlp < 141.0"],"published":"2026-09-10","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:31:11.370","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16172","references":[{"url":"https://support.netskope.com/s/article/Netskope-Security-Advisory-Netskope-Client-Endpoint-DLP-Security-Notice---NSKPSA-2026-008","label":"psirt@netskope.com"}],"tags":["nvd","cve.org"],"epss":0.00114,"epssPercentile":0.0171,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-11T14:55:39.131550Z"},"cvssSource":"cna","ingestedAt":"2026-09-13T09:18:19.346Z","slug":"CVE-2026-16172","body":"## Overview\n\nNetskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver handler. Successful exploitation could potentially crash the EPDLP service, temporarily interrupting DLP enforcement. A successful exploit could potentially also reveal per-boot memory layout information to unauthorized users.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":33,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}