Trellix Agent 5.8.5 release includes feature enhancements and resolved issues.
Release details
For release date and build number details of 5.8.x, see KB51573.
Rating
The rating defines the urgency for installing this update.
This release is mandatory for all environments. You must apply these updates to maintain a viable and supported product.
Enhancements
The Single System Troubleshooting (SST) feature available on ePO - On-prem now allows users to view and collect logs from integrated Trellix point products alongside Agent logs.
The Trellix Agent command-line option now includes the VDI mode status in its output for Windows systems. For details, see the /i parameter description in the Trellix Agent 5.8.x Product Guide.
Upgraded to Jansson version 2.14.1, ZLib version to 1.3.1 and LibCurl version to 8.15.
Implemented support for the fapolicyd security framework from version 1.1 on RPM-based Linux systems. For details, see KB13570, KB14844.
A new command line option (-m) is available to verify the signatures of Trellix binaries for message bus communication with Trellix Agent. For details see -m parameter description in the Trellix Agent 5.8.x Product Guide.
The 5.8.5 Msgbuscertupdater package includes ml_cacerts.cer with new license manager certificates to ensure compatibility with Trellix point products and services. For more details, see KB14338.
Resolved issues in Trellix Agent 5.8.5
Security
Reference | Reference |
|---|---|
MA-14894 | Fixes a critical security vulnerability by implementing enhanced self-protection to prevent process hollowing attacks on Agent process with Trellix Endpoint Security for Windows (ENSW) from 10.7.19. |
Installation
Reference | Resolution |
|---|---|
MA-17073 | Fixes the issue where the systemctl command on RPM-based Linux systems incorrectly reported the agent service status as "failed" or "inactive" after upgrading to version 5.8.3/5.8.4. |
MA-17162 | Resolves an issue that prevented complete Trellix Agent uninstallation via ePO on Debian/Ubuntu clients using external Debian repositories. |
Product manageability
Reference | Resolution |
|---|---|
MA-15942 | Resolves an intermittent Trellix Agent extension upgrade failure that displayed a "No such command" error. |
MA-16259 | Fixes an issue where AMCore content update failed by setting a valid flag in openssl. |
MA-16632 | Disabling the 'TrellixHttp Fallback' feature no longer causes unintended modifications to the Trellix Default Repository policy in ePO. |
MA-16689 | The MER tool is now incorporated into Trellix Agent 5.8.5 packages for Linux and Macintosh systems. For details, see KB83005. |
MA-16801 | Fixes the Full Disk Access (FDA) pop-up issue on macOS systems during Agent upgrade in presence of DLP. |
MA-16900 | The Trellix Agent common service (macmnsvc) no longer binds to port 8081 when Peer-to-Peer and Relay features are disabled. For details, see KB15183. |
MA-16918 | Resolves engine update failures on RPM systems by implementing support for fapolicyd version 1.1 and later. |
MA-17001 | Fixes an intermittent issue where the Trellix Agent Status Monitor failed to launch on Windows systems due to the use of short install path. |
Data Exchange Layer
Reference | Reference |
|---|---|
DXLM-7526 | Fixes the insecure permission issue for the DXL installer log on Linux. |
DXLM-7553 | Resolves a customer issue where 'DXLPrivateKey.pem' protection prevented backups from completing successfully on systems with UEFI partitions. |
Known issues
For a list of known issues, see Known Issues (KB96738).
Additional information
Trellix Agent compatibility with other products
To view the list of products and versions that are compatible with Trellix Agent 5.8.x release, see KB96739.