Skip to main content
Vulnerability Database/CVE-2026-15710

CVE-2026-15710: Netskope Client Information Disclosure Flaw

CVE-2026-15710 is an information disclosure vulnerability in Netskope Client for Windows that exposes DLP configuration, session tokens, and kernel memory to local attackers. This article covers technical details, affected versions, security impact, and recommended mitigations.

Published:

CVE-2026-15710 Overview

CVE-2026-15710 is an information leakage vulnerability in the Endpoint Data Loss Prevention (DLP) component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. The kernel driver exposes an internal communication channel used by a user-space hook DLL to relay messages to the Netskope daemon. That channel lacks token-based validation and returns uninitialized reply buffers to callers. A local unprivileged process can query the channel to read DLP configuration, extract live session tokens, and recover residual kernel pool memory belonging to other users. The issue is tracked under CWE-908: Use of Uninitialized Resource.

Critical Impact

Local unprivileged users can exfiltrate session tokens and read kernel memory fragments from other users' operations through the Netskope Endpoint DLP driver.

Affected Products

  • Netskope Client for Windows prior to version R141
  • Endpoint DLP driver component epdlpdrv.sys
  • Windows endpoints running the Netskope user-space hook DLL and daemon

Discovery Timeline

  • 2026-09-11 - CVE-2026-15710 published to the National Vulnerability Database
  • 2026-09-18 - Last updated in NVD database

Technical Details for CVE-2026-15710

Vulnerability Analysis

The Netskope Endpoint DLP kernel driver epdlpdrv.sys exposes a Local Procedure Call style port used by the user-space hook DLL to send messages through the kernel to the DLP daemon. Two defects combine to create the information disclosure condition.

First, the port message handler accepts requests without token-based authentication of the caller. Any local process, regardless of privilege level, can open the channel and issue queries reserved for the trusted hook DLL. Second, the reply buffer returned by the handler is not zero-initialized before it is populated and returned to the caller. When responses are shorter than the allocated buffer, residual bytes from prior kernel pool allocations remain readable.

An attacker chaining both flaws can enumerate DLP policy configuration, feature flags, and live session tokens issued by the Netskope daemon. Repeated queries progressively disclose kernel pool contents belonging to other users' operations processed on the same system.

Root Cause

The root cause is the absence of caller validation on an internal kernel-to-user communication port combined with a missing memory initialization step in the response path. The driver assumes messages arrive only from the legitimate hook DLL and does not clear the response buffer before copying variable-length data into it.

Attack Vector

Exploitation requires local access with low privileges and no user interaction. An attacker runs an unprivileged process that opens the driver's message port, issues crafted queries, and reads the returned buffers. No memory corruption or code execution primitive is needed; the primitive is a pure read side channel exposed through an under-validated interface. Refer to the Netskope Security Advisory NSKPSA-2026-006 for vendor-provided technical details.

Detection Methods for CVE-2026-15710

Indicators of Compromise

  • Unprivileged processes opening handles to the epdlpdrv.sys communication port that historically only the Netskope hook DLL uses.
  • Unexpected processes issuing repeated port message queries to the Netskope DLP driver interface.
  • Netskope session tokens appearing in the memory or output of processes unrelated to the Netskope client stack.

Detection Strategies

  • Baseline the set of processes that legitimately load the Netskope hook DLL and alert on any deviation querying the DLP driver.
  • Monitor kernel object access telemetry for handle-open events targeting the epdlpdrv device or ALPC port from non-Netskope binaries.
  • Correlate DLP driver interactions with process image path and signing certificate to identify unsigned or unexpected callers.

Monitoring Recommendations

  • Enable Windows kernel auditing and EDR telemetry for driver IOCTL and ALPC message traffic to Netskope components.
  • Track installed Netskope Client versions across the fleet and flag hosts still running versions prior to R141.
  • Alert on unprivileged processes reading buffers containing patterns consistent with Netskope session tokens or DLP policy identifiers.

How to Mitigate CVE-2026-15710

Immediate Actions Required

  • Upgrade the Netskope Client for Windows to version R141 or later on all managed endpoints.
  • Inventory endpoints for vulnerable driver versions of epdlpdrv.sys and prioritize hosts that handle sensitive DLP-monitored data.
  • Rotate any Netskope session tokens or credentials that may have been exposed on unpatched systems.

Patch Information

Netskope has addressed the vulnerability in Netskope Client for Windows R141. The fix adds token-based validation for messages sent through the kernel driver port and initializes reply buffers before returning data. Consult the Netskope Security Advisory NSKPSA-2026-006 for the authoritative patch matrix and upgrade guidance.

Workarounds

  • No vendor-approved workaround replaces the R141 update; disabling the Endpoint DLP component removes protection and is not recommended.
  • Restrict interactive and remote logon rights on sensitive hosts to reduce the population of local users who could exploit the flaw.
  • Apply application allowlisting to prevent execution of untrusted binaries that could query the DLP driver interface.
bash
# Configuration example: verify installed Netskope Client version on Windows
reg query "HKLM\SOFTWARE\Netskope\Provisioning" /v version
# Confirm epdlpdrv.sys file version meets or exceeds the R141 release
powershell -Command "(Get-Item 'C:\Program Files (x86)\Netskope\STAgent\epdlpdrv.sys').VersionInfo"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.