Netskope Client and Endpoint DLP
CVE-2023-4996: Local privilege escalation
Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Netskope Client (Windows) 100 & prior | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code when called by a Windows ServiceController did not validate the permissions associated with the user before executing the user control code. This user control code had permissions to terminate the NSClient service.
Exploitation
Netskope is not aware of any public exploitations of the issue till the advisory is published.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.