Netskope Client and Endpoint DLP

CVE-2025-5942: Heap Overflow in Netskope Endpoint DLP Driver

Netskope was notified about a potential gap in its agent (NS Client) on Windows systems.

Published

ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityMEDIUMCVSS 4.0 5.7
EPSS0.14%Chance of exploitation in 30 days
Public exploitNot tracked
FixAvailable

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
Netskope Client (Windows) 0126.0.9, 129.0.0 or later

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited, an unprivileged user can trigger a heap overflow in the epdlpdrv.sys driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation can also potentially be performed by an unprivileged user whose NS Client is configured to use Endpoint DLP. A successful exploit can result in a denial-of-service for the local machine.

Am I affected?

Must be using Netskope Endpoint DLP

Workarounds

Some AV and EDR solutions may be able to detect the behaviors associated with exploiting this vulnerability.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.