CVE-2025-11156
BaseFortify
Publication date: 2025-11-28
Last updated on: 2025-11-28
Assigner: Netskope
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netskope | ns_client | 4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-476 | The product dereferences a pointer that it expects to be valid but is NULL. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a flaw in the Netskope agent (NS Client) on Windows systems where a local, authenticated user with Administrator privileges can improperly load the driver as a generic kernel service. Exploiting this flaw causes the system to crash with a Blue Screen of Death, resulting in a Denial of Service (DoS) condition on the affected machine.
How can this vulnerability impact me? :
If exploited, this vulnerability can cause your Windows system to crash unexpectedly, leading to a Denial of Service (DoS). This means the affected machine will become unavailable or unusable until it is restarted or repaired, potentially disrupting operations.