PT-2025-33118 · Netskope · Netskope Client

Thomas Brice

·

Published

2025-08-14

·

Updated

2025-09-01

·

CVE-2025-5941

CVSS v4.0

2.0

Low

VectorAV:L/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Netskope NS Client (affected versions not specified)
Description: Netskope has been notified of a potential issue in its agent (NS Client) where a malicious actor could trigger a memory leak by sending a crafted DNS packet to a machine. Successful exploitation may require administrative privileges on the machine, depending on the exact configuration. A successful exploit could result in user-controllable memory being leaked in a domain name stored on the local machine.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2025-5941

Affected Products

Netskope Client