CVE-2025-11156: Netskope Client

Medium severity, CVSS 5.9. EPSS: 0.1% chance of exploitation in the next 30 days.

Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully exploited, a local, authenticated user with Administrator privileges can improperly load the driver as a generic kernel service. This triggers the flaw, causing a system crash (Blue-Screen-of-Death) and resulting in a Denial of Service (DoS) for the affected machine.

Affected products

  • Netskope Netskope Client: before R132 (fixed in R132)

Published 2025-11-28. Last modified 2026-10-08.