PT-2025-33118 · Netskope · Netskope Client
Thomas Brice
·
Published
2025-08-14
·
Updated
2025-09-01
·
CVE-2025-5941
CVSS v4.0
2.0
Low
| Vector | AV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Netskope NS Client (affected versions not specified)
Description:
Netskope has been notified of a potential issue in its agent (NS Client) where a malicious actor could trigger a memory leak by sending a crafted DNS packet to a machine. Successful exploitation may require administrative privileges on the machine, depending on the exact configuration. A successful exploit could result in user-controllable memory being leaked in a domain name stored on the local machine.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netskope Client