Netskope Client and Endpoint DLP
CVE-2025-5942: Heap Overflow in Netskope Endpoint DLP Driver
Netskope was notified about a potential gap in its agent (NS Client) on Windows systems.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Netskope Client (Windows) 0 | 126.0.9, 129.0.0 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited, an unprivileged user can trigger a heap overflow in the epdlpdrv.sys driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation can also potentially be performed by an unprivileged user whose NS Client is configured to use Endpoint DLP. A successful exploit can result in a denial-of-service for the local machine.
Am I affected?
Must be using Netskope Endpoint DLP
Workarounds
Some AV and EDR solutions may be able to detect the behaviors associated with exploiting this vulnerability.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.