10.0.4

Prev Next

The Endpoint Security (HX) server 10.0.4 release includes resolved issues and known issues.

New features and changes

FIPS/CC compliance

The Endpoint Security (HX) server version 10.0.4 is now compliant with FIPS/CC version 140-2 and Common Criteria NDcPP version 2.2e.

Malware proxy commands

The Endpoint Security (HX) server now enables visibility of 'hx server mal proxy' commands and subcommands.

Note

Trellix recommends upgrading Logon Tracker to version 1.3.3 after the Endpoint Security (HX) server has updated to version 10.0.4.

Important

For customers running in FIPS mode, you will need to reach out to Customer Support after upgrading to HX 10.0.4 to obtain a necessary hotfix.

Resolved issues

This release resolves known issues.

ENDPT-227195

Resolved an issue that caused app_processor and sftaskernode to fail, which prevented tasks from running in the system.

ENDPT-226394

Resolved an issue where the 'False Positive' section of the web UI failed to output the correct information when using search.

ENDPT-226267

Resolved an issue where 'hx server mal proxy' commands and subcommands were hidden.

ENDPT-226483

Resolved an issue where the 'False Positive' section of the web UI showed overlapping "Rule Details" when selecting a rule.

ENDPT-227610

Resolved an issue where certain log-files were not included in the regular log-rotation.

Reference

Resolution

Known issues

The following issues are known in the Endpoint Security (HX) server 10.0.4 release.

Reference

Description

ENDPT-26712

The Server API limit parameter and filters are not working as expected for the host containment unlock code feature.

ENDPT-77120

The files-raw audit is missing a filename for the Path Regex parameter.

ENDPT-104429

If you disabled WinTrust Verification in an earlier release of Endpoint Security (HX) server, you must change the WinTrust Verification setting to Disabled and re-apply the setting after you upgrade to Endpoint Security (HX) server this release because the upgrade process automatically enables WinTrust Verification as the default (and recommended) setting.

Resolved vulnerability issues

Reference

Resolution

CVE-2025-0618

Fixed an issue relating to persistent denial of service. For more information, see the Security Bulletin.

Product compatibility

This release supports the following Trellix product versions:

  • CM Series 10.0.x or later

This release supports the following browsers:

  • Microsoft Edge

  • Google Chrome

  • Firefox

Microsoft Internet Explorer and Safari (macOS) are not supported.

Upgrade support

You can upgrade to the Endpoint Security (HX) server 10.0.4 release from release 5.3.x or later.

Always perform a complete backup of your server before you upgrade it. This ensures you can recover your Endpoint Security (HX) server if a problem occurs during the upgrade. For complete information about backing up and restoring the server, see the Endpoint Security System Administration Guide.

After upgrading your Endpoint Security (HX) server to version 10.0.4, reboot the server. For more information about upgrading your Endpoint Security (HX) server software, see the Endpoint Security System Administration Guide.

Note

Be sure to enable quiesce mode for the Endpoint Security (HX) server before you upgrade it or restore a backup to it.

The HX 4502 model requires an upgrade to IPMI 3.11 and BIOS 1.9. You must install the IPMI upgrade before you upgrade the BIOS. For detailed instructions about upgrading IPMI and BIOS, see the Endpoint Security System Administration Guide.

For more information about deploying the Endpoint Security (HX) server, see the respective Endpoint Security Server Deployment Guide.

Note

The deployment of Endpoint Security (HX) server in a high availability (HA) configuration is not supported.