PT-2024-17138 · Netskope · Netskope Endpoint Dlp

·

CVE-2024-11616

·

Published

2024-12-19

·

Updated

2024-12-19

CVSS v4.0

5.6

Medium

VectorAV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Netskope Endpoint DLP versions prior to R119
Description A security issue arises from a double-fetch problem in the Content Control Driver of Netskope Endpoint DLP, leading to a heap overflow. This occurs because the NumberOfBytes argument to ExAllocatePoolWithTag and the Length argument for RtlCopyMemory both independently dereference their value from the user-supplied input buffer inside the EpdlpSetUsbAction function. If the length value increases between these two calls, it results in the RtlCopyMemory call copying user-supplied memory contents outside the allocated buffer, causing a heap overflow. An attacker needs admin privileges to exploit this issue.
Recommendations For versions prior to R119, update to version R119 or later to resolve the issue. As a temporary workaround, consider restricting access to the EpdlpSetUsbAction function until a patch is available. Additionally, ensure that only trusted users have admin privileges to minimize the risk of exploitation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11616

Affected Products

Netskope Endpoint Dlp