Resolved issues

Prev Next

The following issues were resolved in the Endpoint Security Agent (HX) 36.30.17 release.

Tracking number

Summary

ENDPT-104045

Fixed an issue with the BitDefender software development kit that prevented alert information from appearing in scan results for a registry event.

ENDPT-105347

Fixed an issue where DNS hostnames appeared incorrectly for Enterprise Search results on agents using Firefox browser.

ENDPT-112572

Fixed an issue where the rte-sensor failed when the sensor was enabled during event handling for agents running on Linux.

ENDPT-112889

ENDPT-226471

Exclusive access has been added to the Real-Time event database during the cleanup operation. This feature obstructs errors that prevent the storage of new events.

Fixed an issue where the Real-Time event processing engine unloaded old Indicators of Compromise (IOC) content while new content was being loaded.

ENDPT-112973

Added support to protect the agent from Windows Filtering Platform (firewall) rules created by third parties to target the agent.

ENDPT-113183

Fixed an issue where multiple processes shared working directories causing excessive memory usage in the rte-sensor.

ENDPT-225881

Fixed an issue where the FireEye Helper.app (system extension) was enabled in the permissions feature on macOS. This caused the macOS to attempt to close the application during logoff, preventing users from turning off their computer.

ENDPT-226228

Fixed an issue that corrupted the driver's internal file event tracking cache, causing a “bug check” in a Windows environment.

ENDPT-226596

ENDPT-226531

Fixed an issue where the removal of the Windows Filtering platform rules and related context data used to track network events was incorrectly sequenced. This caused the system to fail when the agent was shut down in a Windows environment.

ENDPT-225736

Fixed an issue where the agent failed to implement the policy’s PAC file during startup. This caused connection problems between the agent and the Endpoint Security (HX).

ENDPT-226809

Process event command lines now remove extra white spaces before the command line parameter added by the operating system in a Windows environment. This permits correct IOC matching for indicators that are entered in the command line.

ENDPT-226082

Fixed an issue that caused the agent to fail during an upgrade due to the presence of agent files from a prior version found on the system.

ENDPT-113029

Fixed an issue where an excessive number of events buffered by the Linux Real-Time event collection sensor caused the sensor to fail.

ENDPT-226146

Updated package dependencies within the Linux Real-Time event sensor (rte-sensor) to address:

  • CVE-2023-29403

  • CVE-2023-39325

  • CVE-2023-29406

  • CVE-2024-24786

  • CVE-2023-45288