CVE-2024-11616 - CVE House
Back to Database
Status published Medium CVE-2024-11616

Double-fetch heap overflow

Vulnerability Description

Netskope was made aware of a security vulnerability in Netskope Endpoint DLP’s Content Control Driver where a double-fetch issue leads to heap overflow. The vulnerability arises from the fact that the NumberOfBytes argument to ExAllocatePoolWithTag, and the Length argument for RtlCopyMemory, both independently dereference their value from the user supplied input buffer inside the EpdlpSetUsbAction function, known as a double-fetch. If this length value grows to a higher value in between these two calls, it will result in the RtlCopyMemory call copying user-supplied memory contents outside the range of the allocated buffer, resulting in a heap overflow. A malicious attacker will need admin privileges to exploit the issue. This issue affects Endpoint DLP version below R119.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-11616

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Netskope credits Thomas Brice from Oxford Nanopore Technologies for reporting this flaw.

Affected Vendor

Netskope Inc.

View all reports →

Affected Software

Endpoint DLP
Vulnerable Versions:
118.0.0; 0

Timeline

Official Publish: December 19th, 2024
Last Modified: June 9th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)