CVE-2026-2809 PUBLISHED

Endpoint DLP Driver DLL

Assigner: Netskope
Reserved: 19.02.2026 Published: 17.03.2026 Updated: 17.03.2026

Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow a privileged user to trigger an integer overflow within the DLL Injector, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would require the Endpoint DLP module to be enabled in the client configuration. A successful exploit can potentially result in a denial-of-service for the local machine.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.7

Product Status

Vendor Netskope
Product Endpoint DLP Module for Netskope Client
Versions Default: unaffected
  • affected from 0 to 132.0.20, 135 (excl.)

Affected Configurations

The Endpoint DLP module must be enabled in the client configuration

Workarounds

There are no direct workarounds. Some AV and EDR solutions may be able to detect behaviors associated with exploiting this vulnerability.

Credits

  • Tom Brice reporter

References

Problem Types

  • CWE-190 Integer overflow or wraparound CWE

Impacts

  • CAPEC-92 Forced Integer Overflow