Trellix Data Loss Prevention – SaaS 2307 Release Notes

Prev Next

Trellix DLP – SaaS 2307 includes enhancements and resolved issues.

Product rebranding changes

This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix DLP Endpoint - SaaS as usual. You will notice McAfeeDLPAgentService is renamed as TrellixDLPAgentService.

Trellix DLP – SaaS release information

Release Date - July 11, 2023

This release of Trellix DLP – SaaS is identified as version 2307, where the version identifier follows a yymm convention. The Trellix DLP – SaaS 2307 - July release is updated for Trellix DLP Endpoint - SaaS for Windows, Trellix DLP Discover – SaaS, Trellix DLP Network Monitor – SaaS, and Trellix DLP Network Prevent – SaaS.

Trellix DLP – SaaS is a unified solution and includes the products mentioned here:

  • Trellix Device Control – SaaS

  • Trellix DLP Discover – SaaS

  • Trellix DLP Endpoint - SaaS for Windows

  • Trellix DLP Endpoint - SaaS for Mac

  • Trellix DLP Network Monitor – SaaS

  • Trellix DLP Network Prevent – SaaS

Trellix DLP – SaaS provides support for the following versions of Trellix DLP

Product

Supported versions

Trellix DLP Discover

11.10.401.8

Trellix DLP Endpoint for Mac

11.6.4.73

Trellix DLP Endpoint for Windows

11.10.100.17

Trellix DLP Network Monitor appliance installation images

11.10.301

  • For VMware vSphere virtual appliance — Trellix-MS-11.10.301-3656.100.ms.hw10.hdd.ova

  • For hardware appliance — Trellix-MS-11.10.301-3656.100.iso

Trellix DLP Network Prevent appliance installation images

11.10.301

  • For VMware vSphere virtual appliance — Trellix-PS-11.10.301-3656.100.ps.hw10.hdd.ova

  • For Windows Hyper-V — Trellix-PS-11.10.301-3656.100.HyperV_ps.zip

  • For hardware appliance — Trellix-PS-11.10.301-3656.100.iso



Every update release is cumulative and includes all features and fixes from the previous release. For the previous release information, see:

For more information about using Trellix DLP – SaaS, see the Trellix DLP – SaaS Product Guide.

Upgrade paths not supported

Upgrade from Trellix DLP Endpoint - SaaS for Windows 2212 (11.6.700) and 2303 (11.6.701.4) to 2307 (11.10.100) is not supported if you are running Windows 7 service pack 1, Windows 2012 R2, or Windows 8.1. However, you can still install Trellix DLP Endpoint 11.10.100 for the first time on Windows 7 service pack 1, Windows 2012 R2, or Windows 8.1.

Important

Trellix DLP Endpoint - SaaS for Windows 2307 (11.10.100) for the first time on Windows 7 requires the SHA-2 code signing support update, You can learn more about SHA-2 code signing support update at Microsoft support.

New or Enhanced features

This release includes new or improves the existing features:

Updated platform, environment, or operating system support

You can get the latest information about supported platforms, environments, and operating systems from these KB articles:

  • For Trellix DLP Discover – SaaS: KB94670

  • For Trellix DLP Endpoint - SaaS: KB92445

  • For Trellix DLP Network Monitor – SaaS: KB93790

  • For Trellix DLP Network Prevent – SaaS: KB93790

Resolved issues

Resolved - Vulnerability issues

Reference

Resolution

CVE-2023-0286

SB10395

This release fixes a type confusion vulnerability in which the public structure definition for GENERAL_NAME incorrectly specified the type x400 address field as ASN1_TYPE. For more information about vulnerability and remediation, see SB10395

CVE-2022-4304

SB10395

This release fixes a vulnerability in Open SSL RSA decryption that was caused by an improper timing-based side channel. For more information about vulnerability and remediation, see SB10395

CVE-2023-0215

SB10395

Fixed a vulnerability issue with the PEM_read_bio_ex() function, which reads a Privacy Enhanced Mail (PEM) file and returns a failure code, but still populates the name, header, and payload information. For more information about vulnerability and remediation, see SB10395

CVE-2022-4450

SB10395

Fixed a vulnerability with the public-facing API function BIO_new_NDEF. For more information about vulnerability and remediation, see SB10395



Trellix DLP Extension resolved issue

Reference

Resolution

DLPO-11736

Fixed an issue where the Incident Management page failed to display the list of incidents when the date range was set to a single day.

DLPO-12133

Fixed an issue where an incorrect error message was displayed when classified texts were uploaded to a browser.

Trellix Data Loss Prevention Endpoint – SaaS for Windows resolved issues

Reference

Resolution

DLPW-7497, DLPW-8797

This release improves the performance of an endpoint system by updating the algorithms used in Trellix DLP Endpoint - SaaS.

DLPW-7728

Fixed an issue where the Exceptions defined for manually classified .msg files did not execute for Web Protection Rules.

DLPW-7737

Fixed an issue where the HdlpDiag tool reported Trellix Agent status as disconnected when the policy size was beyond 20Mb.

DLPW-8055

This fix prevents file copying from PowerShell ISE to removable media devices.

DLPW-8075

Resolved a file upload issue by adding %OpticalDrive% to the beginning of the file path in ignored processes.

DLPW-8138

Fixed an issue where Trellix DLP automatically installed Microsoft Visual C++ 2010 as a prerequisite.

DLPW-8191

Fixed an issue where Trellix DLP failed to block a concatenated ZIP and JPEG files containing sensitive Information.

DLPW-8192

Fixed an issue where delays were seen when accessing data from network shares.

DLPW-8250

Fixed an issue where Trellix DLP Endpoint - SaaS could not block the printing of PDF when custom document properties are used in the classifications.

DLPW-8296

This fix prevents copying sensitive content from PowerShell.exe and cmd.exe to Notepad.

DLPW-8310

Fixed an issue where the True File Type classification prevented .mov files from being transferred to a removable storage devices.

DLPW-8359

Fixed a false positive issue where the incidents were generated when the Application File-Access Protection rule was used in Microsoft Teams.

DLPW-8670

Fixed an issue where URL information was missing when outlook.office.com was opened in a pop-up window from Chromium browsers.

DLPW-8848

Fixed an issue where DLP web incidents report "Failure Reason: Text upload blocking is not available" when Timeout reaction is set to Block for text uploads.

DLPW-8865

Fixed an issue where Titus Classification was enabled in Microsoft Outlook that caused it to crash and the email was not saved.

DLPW-8877

Fixed an issue where Google Chrome and Microsoft Edge crashed and failed to launch after a Web Protection rule was created and assigned.

DLPW-9713

Fixed an issue with Trellix DLP Endpoint - SaaS that caused some files to disappear from the My Documents folder in rare circumstances.

Trellix DLP Network Prevent – SaaS and Trellix DLP Network Monitor – SaaS resolved issues

Reference

Resolution

DLPN-12474

This release fixes an issue where the System Health dashboard of an appliance showed high disk usage because of /logs. With this fix, the remote LDAP counters are not logged for non-existent LDAP servers in /logs/realtime/.

DLPN-12522

MegaSys.log shown in the root directory of Trellix DLP 7700 appliance used with DLP Capture Storage Array consumed huge disk space. With this fix, the MegaSys.log file is no longer available in /root directory.

Starting with this release, the MegaCLI is replaced with Storage Command Line Tool (StorCLI), which allows Command Line Tools to manage and control LSI MegaRAID controllers.

DLPN-12565

This release resolves an issue where the MIB file upload to an SNMP tool failed because the identifier could not start or end with a special character.

Trellix DLP Discover – SaaS resolved issues

There are no resolved issues in this release.

Known issues

For a list of current known issues, see: Trellix Data Loss Prevention - SaaS Known Issues.

Comparison of Trellix DLP – SaaS with Trellix DLP on-premises

is working toward feature parity with the on-premises Trellix DLP product. To know more about the options not available in this release, see KB94965.