Trellix Data Loss Prevention Endpoint for Windows 11.11.0 Release Notes

Prev Next

The Trellix DLP Endpoint for Windows 11.11.0 release includes new features and resolved issues.

Release details

Release date - April 25, 2024

Release builds:

  • Trellix Data Loss Prevention Endpoint client build 11.11.0.138

If you have previously installed 11.11.0.118, it is recommended to update it to 11.11.0.138 before you continue testing/deploying.

Note

Trellix DLP Endpoint 11.11.0.138 requires Trellix DLP 11.11.1.3 extension. Trellix DLP Endpoint client software is not compatible with earlier versions of Trellix DLP extensions.

For the specific build numbers, see Product release information in KB68147.

Supported upgrade path

Upgrade from...

To

11.6.700

11.11.0

11.6.800

11.11.0

11.10.100

11.11.0

11.10.200

11.11.0

Updated platform, environment, or operating system support

For additional information on supported platforms, environments, and operating systems, see KB68147.

New or changed features

This release introduces new features or improves existing features:

Integration with Google Chrome Enterprise browser - Trellix DLP Endpoint for Windows can now be seamlessly integrated with Chrome Enterprise using the Content Analysis SDK in Chrome. This improves performance, security and enhanced browsing experience. For more information on the advantages and configuration of integrating with Google Chrome Enterprise browser, see the Integration with Google Chrome Enterprise topic in the Product Guide.

New Outlook support - In this new update, Trellix DLP Endpoint for Windows extends support to monitor and protect sensitive emails sent from Microsoft's New Outlook integrating with Outlook's On-send API.

Support for the Turkish letter ‘İ’ - Trellix DLP Endpoint for Windows now supports Turkish characters with case insensitivity for dictionary and keyword. For example, when a classification is created using a keyword containing the uppercase letter "İ", Trellix DLP converts it to the lowercase letter "i" allowing the rule to trigger.

Note

Trellix DLP Endpoint can not convert to lowercase Turkish letter "ı" Ascii character code (305). However, you can create an entry in Dictionary tab for both "ı" Ascii character code (305) and "i" Ascii character code (105) or you can create an advance pattern to detect all "iıİ".

Manually Resolve DFS - Using this option, you can manually resolve network share paths of all the child nodes of DFS shares and enter them individually in the network definitions. Alternatively, if you uncheck this option, Trellix DLP Endpoint resolves all child nodes' share paths of the DFS share paths mentioned in the network definition. To enable Manual DFS Share navigate to Policy CatalogData Loss Prevention <version>Windowsedit a policySettingsAdvanced Configuration.

Removed feature

Important

Trellix DLP 11.11.0 will not include the Island browser integration that was introduced as a beta feature in Trellix DLP for Windows 11.10.200. However, we are in the process of working with the Island team to implement and support this integration in a future release.

Known issues

For a list of current known issues, see: Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).

These were the known issues observed in 11.11.0.118 build which are now removed in 11.11.0.138 build.

Known Issues

Reference

Issue

DLPW-9865

An issue is observed where the Cloud Protection rule doesn't block files uploaded to OneDrive.

DLPW-9275

An issue is observed that tagged Microsoft Office files (Word, Excel, and PowerPoint) and PDF files are not blocked when Save as to USB is selected.



Resolved issues

This update resolves known issues.

For the DLP Extension related resolved issues, see the Trellix Data Loss Prevention Extension 11.11.x Release Notes.

Resolved Vulnerability Issues

Reference

Resolution

CVE-2024-4047, CVE-2024-4048, CVE-2024-4049, CVE-2024-4050, CVE-2024-4051, CVE-2024-4052, CVE-2024-4053, CVE-2024-4054

SB10419

Fixed an issue where the DLP Probe directories and few registry paths were not access protected. For more information about vulnerability and remediation, see SB10419



Resolved Endpoint issues

Reference

Resolution

DLPW-8631

Fixed an issue where the Removable Storage File Access Device rule failed to block file access for CD/DVD devices even when the Device Type was set to CD/DVD and the True File Type was set to Actual File Type.

DLPW-8867

Fixed an issue where Trellix DLP Endpoint moved blocked files to Quarantine folder in plain text when Removable Storage Protection rule's reaction was set to Block.

DLPW-10013

Fixed an issue in Windows 11 where the Plug and Play Device rule failed to block UAS (SCSI) storage devices.

DLPW-10122

Fixed an issue where the USB device was redirected from the host machine to the Citrix virtual machine. This allowed users to access or write to the device even when the Citrix VAD Device Rule (formerly the Citrix XenApp Rule) was applied.

DLPW-10287

Fixed an issue where sensitive files were not blocked when a folder containing sensitive files was dragged and dropped onto Microsoft Teams.

DLPW-10517

Fixed an issue in which the Application File Access Protection rule failed to block files when copied to removable media.

DLPW-10528

Fixed an issue where Microsoft Outlook displayed the following error message when sending an email: "The Send operation failed because the item was deleted before it was sent".

DLPW-11137

Fixed an issue in which evidence files in .pdf format were automatically appended with the .txt extension.

DLPW-11163

An issue that prevented updating to the latest version of Trellix DLP Endpoint 11.10.x has been resolved.

DLPW-11186

Fixed an issue where the Plug and Play Device rule failed to block files printed via USB devices.

DLPW-11657

Fixed a localization issue that occurred after updating Trellix DLP Endpoint to the latest version.

DLPW-11688

Fixed an issue where the RegDocDB.dat file in the WebDAV evidence share path was not downloading to endpoints.