The Trellix EDR with Forensics (EDRF) 50.2.1 release includes resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release.
Release details
Component | Version |
|---|---|
Trellix EDR with Forensics for Linux | 50.2.1.64 |
Trellix EDR with Forensics for Windows | 50.2.1.61 |
For a complete list of supported platforms, see the Trellix Knowledge Base (KB) article, Supported Platforms for Trellix EDR with Forensics - KB000014084.
Rating
This release is critical for all environments. Failure to apply this update might result in potential business impact.
Resolved issues
Linux
Reference | Resolution |
|---|---|
ES-25998, ES-26078 | Resolves an issue where Linux endpoints experienced excessive memory consumption. This update introduces an improved caching mechanism to reduce memory consumption and improve endpoint stability. |
Windows
Reference | Resolution |
|---|---|
ES-25363 | Resolves an issue where upgrading to EDRF Client 50.2.0 caused intermittent issues on SQL servers during process shutdowns or restarts. The underlying filter driver is updated to ensure safe memory access and maintain system stability. |
ES-25452 | Resolves an issue where certain Access Protection rules caused high CPU usage and reduced endpoint performance during heavy registry read operations. This update optimizes the Access Protection rules to reduce system overhead while maintaining the same level of protection. |
ES-25912 | Resolves an issue where heavy network traffic caused the EDRF Client to create Windows Filtering Platform (WFP) filters without releasing them, leading to filter exhaustion and unresponsive servers. This update ensures that filters are properly released. If performance issues persist after the upgrade, restart the appliance to clear the Windows Filtering Platform (WFP) filters. |
ES-25999 | Resolves an issue where endpoints experienced network instability due to Windows Filtering Platform (WFP) filter leaks. The EDRF Client installer now automatically applies a mitigation during fresh installations and product upgrades to prevent the accumulation of filters under high load and maintain stable network performance. |
Known issues
For a list of current known issues in this product release, see the Trellix Knowledge Base article, EDR with Forensics Known Issues - KB000014081.