Application and Change Control 8.4.4 Hotfix 2 Release Notes

Prev Next

This hotfix contains resolved issues.

Release date — October 30, 2025

Release build:

TACC Extension — 8.4.4.155

TACC Client — 8.4.4.285

This hotfix build was developed and tested with:

  • Trellix ePolicy Orchestrator® 5.10.x

Note: This hotfix does not support the automatic upgrade of a pre-release software version. To upgrade to a production release of the software, you must first uninstall any pre-release versions.

Rating:

The rating defines the urgency for installing this hotfix.

This hotfix is recommended for all environments. Apply this hotfix at your earliest convenience.

What’s new

  • Exclusive TIE Enterprise reputation source

    This release introduces an enhancement to the Trellix Threat Intelligence Exchange (TIE) integration. A new TIE Enterprise Trust Level option is now available in the Application Control Options  (Windows) policy.


    When you enable this option, Application Control uses TIE Enterprise as the exclusive source for file reputations, disabling the use of Trellix Global Threat Intelligence (GTI) and Trellix Advanced Threat Defense (ATD) reputations.


    Note the following behavior for this feature:

    • The TIE Enterprise Trust Level option can only be configured in the policy through Trellix ePO; it cannot be modified on the endpoint.

    • When this option is enabled in the policy, the Trellix GTI reputation feature cannot be enabled by a user on the endpoint.

    • If a user disables the TIE reputation feature on the endpoint, both the TIE reputation feature and the TIE Enterprise Trust Level setting are disabled locally, with the trust level resetting to zero.


    To improve visibility, a new TieEnterpriseLevelTrustEnable property has been added to the System Tree. This property displays the status of the TIE Enterprise Trust Level for each endpoint, allowing you to quickly verify whether the setting is enabled or disabled across your environment.

  • Enhanced Reputation Display for TIE Overrides

    To provide a clear context for user-defined reputations, the display format in the Solidcore Events UI has been updated. An (Enterprise) suffix is now added for events generated for files whose reputation was specifically overridden as Malicious by a user through the TIE Reputations UI.

    This applies to events originating from endpoints where the deny reasons are either TIE - Malicious process SHA-1 or TIE - Malicious Certificate.

    The Reputation column in the Solidcore Events UI will now display these overridden reputations as:

    • Known Malicious (Enterprise)

    • Most Likely Malicious (Enterprise)

    • Might Be Malicious (Enterprise)

Resolved issues

This hotfix addresses customer-reported issues.

For a list of current known issues, see KB87839 for Application and Change Control 8.x (Windows).

Reference

Resolution

MACC-15752

Resolves a memory leak issue in TACC associated with the MFEO, QRTt, QRTP, and QRT3                     pool tags.

Installation instructions

For information about installing or upgrading Application and Change Control software, see     Trellix Application and Change Control 8.4.x Installation Guide.

3