CVE-2026-16174
Received Received - Intake

Integer Overflow in Netskope Endpoint DLP on Windows

Vulnerability report for CVE-2026-16174, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Netskope

Description

Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption. Successful exploitation would require the EPDLP module to be enabled in the client configuration, and that Memory Integrity is disabled. A successful exploit could potentially result in a denial-of-service, arbitrary code execution, or privilege escalation on the local machine.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netskope endpoint_dlp *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an integer overflow issue in Netskope Endpoint DLP (EPDLP) on Windows systems. A privileged user could send a crafted message to the EPDLP process port, triggering memory corruption. Exploitation requires the EPDLP module to be enabled and Memory Integrity disabled. Successful attacks may cause denial-of-service, arbitrary code execution, or privilege escalation on the local machine.

Detection Guidance

Detection requires checking if the Netskope Endpoint DLP (EPDLP) module is enabled on Windows systems and if Memory Integrity is disabled. Review Netskope client configurations and Windows security settings. No specific commands are provided in the context.

Impact Analysis

If exploited, this vulnerability could allow an attacker to crash the system, execute arbitrary code, or gain elevated privileges on the local machine. This could lead to unauthorized access, data theft, or system compromise, depending on the attacker's goals.

Compliance Impact

This vulnerability could potentially lead to unauthorized access, data exfiltration, or system compromise on local machines where the Netskope Endpoint DLP (EPDLP) module is enabled. Such incidents may result in violations of data protection regulations like GDPR or HIPAA, depending on the nature of the exposed data and affected systems.

Mitigation Strategies

Enable Memory Integrity in Windows security settings. Disable the EPDLP module in client configurations if not required. Apply patches or updates from Netskope if available. Monitor for unusual activity or crashes on endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16174. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart