CVE-2026-15710
Received Received - Intake

Endpoint DLP Information Leakage in Netskope Client for Windows

Vulnerability report for CVE-2026-15710, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: Netskope

Description

An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper token-based message validation, allowing local unprivileged processes to send unauthorized queries. Additionally, a reply buffer used by the port message handler was not properly initialized before returning data, leaking residual kernel pool memory from prior allocations. A local unprivileged attacker could exploit this vulnerability to enumerate DLP configuration and feature flags, extract live session tokens, and read kernel memory fragments from other users' operations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netskope client r141

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-908 The product uses or accesses a resource that has not been initialized.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an information leakage issue in Netskope Client for Windows before version R141. It exists in the Endpoint DLP component (epdlpdrv.sys) where an internal communication channel lacked proper token validation, allowing local unprivileged processes to send unauthorized queries. Additionally, a reply buffer was not initialized, leaking residual kernel memory from prior operations.

Detection Guidance

This vulnerability involves kernel driver (epdlpdrv.sys) and user-space hook DLL communication in Netskope Client for Windows. Detection requires checking for unauthorized process interactions with the driver or unusual memory access patterns. Monitor for processes querying DLP configuration or session tokens without proper privileges. Use tools like Process Explorer or WinObj to inspect driver communication ports and memory buffers.

Impact Analysis

A local unprivileged attacker could exploit this to read kernel memory fragments, extract live session tokens, and enumerate DLP configuration and feature flags. This could lead to unauthorized access to sensitive data or system information.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized access to sensitive data. Local attackers may extract live session tokens and read kernel memory fragments, which could expose personal or protected health information. Improper validation and memory leakage in the Endpoint DLP component may violate data protection requirements under these regulations.

Mitigation Strategies

Immediately update Netskope Client for Windows to version R141 or later to patch the vulnerability. If updating is not immediately possible, restrict local unprivileged user access to the system or disable the Endpoint DLP component temporarily. Monitor for suspicious activity involving the epdlpdrv.sys driver or unauthorized token queries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15710. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart