A local unprivileged attacker could exploit the information leakage vulnerability in Netskope Client for Windows Endpoint DLP component to enumerate DLP configuration and feature flags, extract live session tokens, and read kernel memory fragments from other users' operations. This vulnerability exists due to improper token-based message validation in an internal communication channel used by the user-spa [truncated]
A potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems could allow a privileged user to send a crafted message to the EPDLP process port, triggering an integer overflow and memory corruption. This issue requires the EPDLP module to be enabled and Memory Integrity to be disabled. The CVE record describes a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Succe [truncated]
A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver handler. Successful exploitation could potentially crash the EPDLP service, temporarily interrupting DLP enforcement. A successful exploit could potentially also reveal per-boot memory layout information to unauthorized users.
A vulnerability was reported in Netskope Client for Windows, where a malicious insider with admin privileges can bypass NSClient Tamper Protections. This is due to weak Discretionary Access Control List (DACLs) on the service object and related registry keys. The affected product is Netskope Client, and the affected platform is Windows, with all versions below R138 being vulnerable.
A potential gap was found in the Netskope Client for Windows systems, allowing a malicious insider with administrative privileges to tamper with the customer IOCTL by sending crafted IOCTL requests to the driver, effectively bypassing all anti-tampering protections for the NSClient. This vulnerability exists in the Netskope Client for Windows, where an administrative insider can send crafted IOCTL request [truncated]