The Trellix DLP Endpoint for Windows 11.11.0 release includes new features and resolved issues.
Release details
Release date - April 25, 2024
Release builds:
Trellix Data Loss Prevention Endpoint client build 11.11.0.138
If you have previously installed 11.11.0.118, it is recommended to update it to 11.11.0.138 before you continue testing/deploying.
Note
Trellix DLP Endpoint 11.11.0.138 requires Trellix DLP 11.11.1.3 extension. Trellix DLP Endpoint client software is not compatible with earlier versions of Trellix DLP extensions.
For the specific build numbers, see Product release information in KB68147.
Supported upgrade path
Upgrade from... | To |
|---|---|
11.6.700 | 11.11.0 |
11.6.800 | 11.11.0 |
11.10.100 | 11.11.0 |
11.10.200 | 11.11.0 |
Updated platform, environment, or operating system support
For additional information on supported platforms, environments, and operating systems, see KB68147.
New or changed features
This release introduces new features or improves existing features:
Integration with Google Chrome Enterprise browser - Trellix DLP Endpoint for Windows can now be seamlessly integrated with Chrome Enterprise using the Content Analysis SDK in Chrome. This improves performance, security and enhanced browsing experience. For more information on the advantages and configuration of integrating with Google Chrome Enterprise browser, see the Integration with Google Chrome Enterprise topic in the Product Guide.
New Outlook support - In this new update, Trellix DLP Endpoint for Windows extends support to monitor and protect sensitive emails sent from Microsoft's New Outlook integrating with Outlook's On-send API.
Support for the Turkish letter ‘İ’ - Trellix DLP Endpoint for Windows now supports Turkish characters with case insensitivity for dictionary and keyword. For example, when a classification is created using a keyword containing the uppercase letter "İ", Trellix DLP converts it to the lowercase letter "i" allowing the rule to trigger.
Note
Trellix DLP Endpoint can not convert to lowercase Turkish letter "ı" Ascii character code (305). However, you can create an entry in Dictionary tab for both "ı" Ascii character code (305) and "i" Ascii character code (105) or you can create an advance pattern to detect all "iıİ".
Manually Resolve DFS - Using this option, you can manually resolve network share paths of all the child nodes of DFS shares and enter them individually in the network definitions. Alternatively, if you uncheck this option, Trellix DLP Endpoint resolves all child nodes' share paths of the DFS share paths mentioned in the network definition. To enable Manual DFS Share navigate to Policy Catalog → Data Loss Prevention <version> → Windows → edit a policy → Settings → Advanced Configuration.
Removed feature
Important
Trellix DLP 11.11.0 will not include the Island browser integration that was introduced as a beta feature in Trellix DLP for Windows 11.10.200. However, we are in the process of working with the Island team to implement and support this integration in a future release.
Known issues
For a list of current known issues, see: Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).
These were the known issues observed in 11.11.0.118 build which are now removed in 11.11.0.138 build.
Reference | Issue |
|---|---|
DLPW-9865 | An issue is observed where the Cloud Protection rule doesn't block files uploaded to OneDrive. |
DLPW-9275 | An issue is observed that tagged Microsoft Office files (Word, Excel, and PowerPoint) and PDF files are not blocked when Save as to USB is selected. |
Resolved issues
This update resolves known issues.
For the DLP Extension related resolved issues, see the Trellix Data Loss Prevention Extension 11.11.x Release Notes.
Reference | Resolution |
|---|---|
CVE-2024-4047, CVE-2024-4048, CVE-2024-4049, CVE-2024-4050, CVE-2024-4051, CVE-2024-4052, CVE-2024-4053, CVE-2024-4054 | Fixed an issue where the DLP Probe directories and few registry paths were not access protected. For more information about vulnerability and remediation, see SB10419 |
Reference | Resolution |
|---|---|
DLPW-8631 | Fixed an issue where the Removable Storage File Access Device rule failed to block file access for CD/DVD devices even when the Device Type was set to CD/DVD and the True File Type was set to Actual File Type. |
DLPW-8867 | Fixed an issue where Trellix DLP Endpoint moved blocked files to Quarantine folder in plain text when Removable Storage Protection rule's reaction was set to Block. |
DLPW-10013 | Fixed an issue in Windows 11 where the Plug and Play Device rule failed to block UAS (SCSI) storage devices. |
DLPW-10122 | Fixed an issue where the USB device was redirected from the host machine to the Citrix virtual machine. This allowed users to access or write to the device even when the Citrix VAD Device Rule (formerly the Citrix XenApp Rule) was applied. |
DLPW-10287 | Fixed an issue where sensitive files were not blocked when a folder containing sensitive files was dragged and dropped onto Microsoft Teams. |
DLPW-10517 | Fixed an issue in which the Application File Access Protection rule failed to block files when copied to removable media. |
DLPW-10528 | Fixed an issue where Microsoft Outlook displayed the following error message when sending an email: "The Send operation failed because the item was deleted before it was sent". |
DLPW-11137 | Fixed an issue in which evidence files in .pdf format were automatically appended with the .txt extension. |
DLPW-11163 | An issue that prevented updating to the latest version of Trellix DLP Endpoint 11.10.x has been resolved. |
DLPW-11186 | Fixed an issue where the Plug and Play Device rule failed to block files printed via USB devices. |
DLPW-11657 | Fixed a localization issue that occurred after updating Trellix DLP Endpoint to the latest version. |
DLPW-11688 | Fixed an issue where the RegDocDB.dat file in the WebDAV evidence share path was not downloading to endpoints. |