2026-04-29 15:23CVE-2026-2810Netskope
PUBLISHED5.2CWE-125

Endpoint DLP Driver Out-of-Bounds Read

Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an out-of-bounds read within a driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.

Problem type

Affected products

Netskope

Client

< 129.1.8,132.0.23,135.1.0,136.1 - AFFECTED

References

GitHub Security Advisories

GHSA-4wwp-q772-ccjv

Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on...

https://github.com/advisories/GHSA-4wwp-q772-ccjv

Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an out-of-bounds read within a driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-2810
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-2810",
    "assignerOrgId": "bf992f6a-e49d-4e94-9479-c4cff32c62bc",
    "assignerShortName": "Netskope",
    "dateUpdated": "2026-04-29T15:23:11.592Z",
    "dateReserved": "2026-02-19T15:53:21.190Z",
    "datePublished": "2026-04-29T15:23:11.592Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "bf992f6a-e49d-4e94-9479-c4cff32c62bc",
        "shortName": "Netskope",
        "dateUpdated": "2026-04-29T15:23:11.592Z"
      },
      "datePublic": "2026-04-29T15:30:00.000Z",
      "title": "Endpoint DLP Driver Out-of-Bounds Read",
      "descriptions": [
        {
          "lang": "en",
          "value": "Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an out-of-bounds read within a driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an out-of-bounds read within a driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine."
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Netskope",
          "product": "Client",
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "129.1.8,132.0.23,135.1.0,136.1"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-125 Out-of-bounds read",
              "cweId": "CWE-125",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.netskope.com/resources/netskope-resources/netskope-security-advisory-nskpsa-2026-002",
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://support.netskope.com/s/article/Netskope-Security-Advisory-NSKPSA-2026-002-Netskope-Endpoint-DLP-Driver-Security-Advisory",
          "tags": [
            "vendor-advisory"
          ]
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-540",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-540 Overread Buffers"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "configurations": [
        {
          "lang": "en",
          "value": "The Endpoint DLP module must be enabled in the client configuration.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "The Endpoint DLP module must be enabled in the client configuration."
            }
          ]
        }
      ],
      "workarounds": [
        {
          "lang": "en",
          "value": "There are no direct workarounds. Some AV and EDR solutions may be able to detect behaviors associated with exploiting this vulnerability.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "There are no direct workarounds. Some AV and EDR solutions may be able to detect behaviors associated with exploiting this vulnerability."
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Tom Brice",
          "type": "reporter"
        }
      ]
    }
  }
}