CVE-2026-16174

8.7

Netskope · Endpoint DLP

A memory corruption vulnerability in Netskope Endpoint DLP for Windows allows a privileged user to trigger an integer overflow, potentially leading to arbitrary code execution or privilege escalation.

Executive summary

A high-severity memory corruption vulnerability in Netskope Endpoint DLP for Windows could allow a privileged local user to achieve arbitrary code execution or system escalation.

Vulnerability

This vulnerability is an integer overflow (CWE-190) occurring within the Netskope Endpoint DLP process port. It requires the attacker to possess high privileges on the local machine, have the EPDLP module enabled, and have Windows Memory Integrity disabled to successfully execute the attack.

Business impact

The potential for arbitrary code execution and privilege escalation poses a significant risk to organizational endpoints. Successful exploitation could allow an attacker to gain full control over affected machines, leading to unauthorized data access, lateral movement within the network, or complete system compromise. The CVSS score of 8.7 confirms the high severity of this flaw, necessitating prompt attention despite the requirement for local privileged access.

Remediation

Immediate Action: Update the Netskope Endpoint DLP client to version 141.0 or later immediately to resolve the memory overflow vulnerability.

Proactive Monitoring: Monitor endpoint logs for suspicious activity targeting the EPDLP process port or abnormal memory utilization patterns.

Compensating Controls: Ensure that Windows Memory Integrity is enabled across all endpoints to provide a critical layer of defense against memory corruption attacks.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Given the potential for full system compromise, IT administrators should prioritize the deployment of the 141.0 update to all Windows endpoints running the Netskope Endpoint DLP module. Organizations should verify that Windows Memory Integrity is active, as this serves as a critical defense-in-depth measure against this class of memory-based vulnerabilities. Regular patch management cycles for security agents are essential to maintaining a hardened security posture.

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources