A double-fetch vulnerability exists in Netskope Endpoint DLP's Content Control Driver, specifically in the EpdlpSetUsbAction function. The function independently fetches a user-supplied length value for both memory allocation (ExAllocatePoolWithTag) and memory copy (RtlCopyMemory). If the value is changed between these two fetches, RtlCopyMemory may copy more data than was allocated, resulting in a heap overflow. Exploitation requires administrative privileges. Affected versions are below R119.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for a double-fetch race condition vulnerability in the Netskope Endpoint DLP Content driver on Windows. The main code file, 'epdlp_usb_action_poc.cpp', is a C++ program that must be run with administrator privileges. It allocates a specially crafted structure and uses a high-priority thread to rapidly flip a value in memory, while repeatedly sending this structure to the driver via the '\EpdlpPort' communication port. The exploit also forcibly terminates the 'epdlp.exe' process to manipulate the state of the DLP service. If successful, this triggers a race condition in the driver, resulting in a Blue Screen of Death (BSOD) on the target system. The repository is structured as a typical Visual Studio C++ project, with solution and project files, and contains only one code file implementing the exploit logic. No network or remote attack vector is present; the exploit is local and targets a specific driver interface.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.