Trellix Data Loss Prevention Endpoint for Windows 11.11 Update 2 (11.11.2) Release Notes

Prev Next

The Trellix DLP Endpoint for Windows 11.11 Update 2 (11.11.2) release includes a changed feature and changes to the libraries.

Release details

Release date - December 11, 2024

Release builds:

  • Trellix Data Loss Prevention Endpoint client build 11.11.2.1172

If you have previously installed 11.11.1.74, we recommend updating it to 11.11.2.1172 before you continue testing or deploying.

For the DLP Extension resolved issues, see the Trellix Data Loss Prevention Extension 11.11.x Release Notes.

Note

Trellix DLP Endpoint 11.11.2.1172 requires Trellix DLP 11.11.4.23 extension. Trellix DLP Endpoint client software is not compatible with the earlier versions of Trellix DLP extensions.

For the specific build numbers, see Product release information in KB68147.

Updated platform, environment, or operating system support

For additional information on supported platforms, environments, and operating systems, see KB68147.

Minor update or fixes

This release includes following enhancements to improve theoverall product performance:

Application File Access Protection (AFAP) Rule enhancements - AFAP rule hooks are now injected only into processes configured for inspection in the AFAP rule, enhancing the overall performance of the product.

Enhanced performance with additional Microsoft Ignored Processes - This release introduces 26 additional Microsoft ignored processes to the Clipboard Protection and Content Tracking pages. These ignored processes optimize the performance of the product.

New built-in custom validators - Trellix Data Loss Prevention has introduced 13 built-in custom validators to accurately validate Personally Identifiable Information (PII) and Financial Account Information. These validators are designed to streamline data validation processes, ensuring compliance with regional regulatory standards and improving the accuracy of sensitive data identification.

The newly added validators include:

  1. Argentina CUIT

  2. Indonesia ID

  3. Japan National ID

  4. Malaysia ID

  5. Mexico Bank Account Numbers

  6. Mexico SSN

  7. Turkish ID

  8. UAE ID

See Classification Definitions Reference Guide for detailed information on the regex patterns used for these validators.

Known issues

For a list of current known issues, see: Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).

Resolved issues

This update resolves known issues.

Reference

Resolution

DLPW-8631

Fixed an issue where the Removable Storage File Access Device rule failed to block file access for CD/DVD devices even when the Device Type was set to CD/DVD and the True File Type was set to Actual File Type.

DLPW-8867

Fixed an issue where Trellix DLP Endpoint - SaaS moved blocked files to Quarantine folder in plain text when Removable Storage Protection rule's reaction was set to Block.

DLPW-10013

Fixed an issue with the endpoint machine running Windows 11, where the Plug and Play Device rule failed to block UAS (SCSI) storage devices.

DLPW-10122

Fixed an issue where the USB device was redirected from the host machine to the Citrix virtual machine. This allowed users to access or write to the device even when the Citrix VAD Device Rule (formerly the Citrix XenApp Rule) was applied.

DLPW-10231

Fixed an issue where the Excel files without extensions failed to save in folders with folder names containing dots.

DLPW-10287

Fixed an issue where the sensitive files were not blocked when a folder containing sensitive files was dragged and dropped onto Microsoft Teams.

DLPW-10501

Fixed an issue where the endpoint discovery scan incorrectly identified random 16-digit numbers that did not pass the Luhn check. As a fix, Respect cell boundaries in spreadsheets checkbox is provided in Content TrackingText Extractor page.

To use the Respect cell boundaries in spreadsheets option:

  1. Upgrade the extension.

  2. Select the WCC → Content Tracking option.

  3. Upgrade Trellix DLP Endpoint for Windows.

DLPW-10517

Fixed an issue in which the Application File Access Protection rule failed to block files when copied to removable media.

DLPW-10518

Fixed an issue that caused delays when opening .txt files in a Virtual Desktop Infrastructure (VDI) environment.

DLPW-10528

Fixed an issue where Microsoft Outlook displayed the following error message when sending an email: "The Send operation failed because the item was deleted before it was sent".

DLPW-10921

Fixed an issue that caused the Snipping Tool to crash on endpoints with the Application File Access Protection Rule (AFAPR) enabled and EDR running.

DLPW-11137

Fixed an issue in which evidence files in .pdf format were automatically appended with the .txt extension.

DLPW-11163

An issue that prevented updating to the latest version of Trellix DLP Endpoint 11.10.x has been resolved.

DLPW-11186

Fixed an issue where the Plug and Play Device rule failed to block files printed via USB devices.

DLPW-11269

Fixed an issue where the cloud protection rule did not prevent the files from being uploaded to Microsoft OneDrive.

DLPW-11392

Fixed an issue where false positives were generated when the application file access protection rule was configured on Microsoft Teams.

DLPW-11657

Fixed a localization issue that occurred after updating Trellix DLP Endpoint to the latest version.

DLPW-11688

Fixed an issue where the RegDocDB.dat file in the WebDAV evidence share path was not downloading to endpoints.

DLPW-12497

Fixed an issue where the DLP Incident Manager page did not display URL details when switching between user profiles on the same endpoint machine and uploading the same confidential document.

DLPW-12632

Fixed an issue where incidents were generated for Microsoft 365 Business even if the Office 365 option was unchecked in Cloud Service settings.

DLPW-12634

Fixed an issue that caused the Microsoft sign-in dialog box to appear unexpectedly after updating Trellix DLP Endpoint for Windows to the latest version.

DLPW-12753, DLPW-14479

Fixed an issue that caused fcnm.exe to crash on certain virtual desktop machines.

DLPW-12773

Fixed an issue where the web protection rule failed to block the upload of sensitive text in the body of web-based emails.

DLPW-13679

Fixed an issue where the IsActionTriggered value was inconsistent in the email protection rule when using a recipient threshold condition.

DLPW-13816

Fixed an issue where fcnm.exe was crashing due to heap corruption.

DLPW-14048

Fixed an issue where matched URL details were missing in incidents generated by the Clipboard Protection Rule when the and Destination URL option was set to Is any web URL.