The Netskope client service, running with NT\SYSTEM
privilege, accepts network connections from localhost.
The connection handling function in this service suffers from a command injection vulnerability.
Local users can use this vulnerability to execute code with NT\SYSTEM
privilege.
CWE-78 Command injection
Netskope
Netskope Client on Windows
Local
Yes
An authenticated user can interact with the Netskope Client service through a local network socket and trigger an command injection.
Julien Lenoir, Benoit Camredon, Mouad Abouhali from Airbus Security Lab.
The Netskope client service, running with NT\SYSTEM
privilege, accepts network connections from localhost.
The connection handling function in this service suffers from a stack based buffer overflow in doHandshakefromServer
function.
Local users can use this vulnerability to trigger a crash of the service and potentially cause additional impact on the system.
Stack based buffer overflow
Netskope
Netskope Client on Windows
Local
Memory corruption and denial of service
An authenticated user can interract with the Netskope Client service through a local network socket and trigger an command injection.
Julien Lenoir, Benoit Camredon, Mouad Abouhali from Airbus Security Lab.