The Trellix Application and Change Control 8.4.2 release includes enhancements and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Rating
The rating defines the urgency for installing this update.
This release is recommended for all environments. Apply this update at the earliest convenience.
Release details
For release dates and build numbers, see KB87944.
Upgrade support
This release supports upgrading from:
TACC extension 8.2.x, 8.3.0–8.3.8, 8.4.0, and 8.4.1
When you upgrade from the existing TACC extension, you must not change any existing rules and configuration until the Solidcore: Migration server task is completed. The migration task usually takes a few hours to a day, depending on the inventory data volume of your environment.
Note
Trellix recommends disabling General Policy enforcement before upgrading to TACC 8.4.x from any version earlier to TACC 8.4.x as it can override configuration values integrated with the extension in TACC 8.4.x to their default values. For details, see KB96798.
TACC client 8.2.x, 8.3.0–8.3.7, 8.4.0, and 8.4.1
For information about the TACC extension and client upgrade supported path, see KB87944.
New or changed
Approval Request Management—Denial events requested for approval from the Application and Change Control Events dialog box are now tagged with Approval Request and sent to the Policy Discovery page on the ePO - On-prem console by default. If sending requests to the Policy Discovery page fails due to the unavailability of file information or unsupported event IDs, they are sent to the preconfigured email server. A notification in the Application and Change Control Events dialog box indicates whether the approval request is sent to ePO - On-prem or the email server. With this enhancement in approval request management, a new Approval Request column is introduced on the Policy Discovery and Queries and Reports pages. The Approval Request tag groups Policy Discovery requests along with the checksum and MP violation flag. Actions for Policy Discovery requests remain unchanged. Sending denial event requests to the Policy Discovery page applies only to specific events such as write denial, execution denial, package modification prevented, NX violation, process hijacked, and network path. All other event requests are sent through the email server.
Note
Denial events generated by policy rules or reputation flow will not enter the Policy Discovery flow.
Known issues
For a list of current known issues, see Application and Change Control 8.x Known Issues (KB87839) and KB87838.
Resolved issues
This release resolves known issues.
TACC extension
Category | Reference | Resolution |
|---|---|---|
User interface | MACC-13172 | The Apply rule to events option remains available in SP1 Update 2 after upgrading the TACC extension to version 8.4.2. |
TACC client
Category | Reference | Resolution |
|---|---|---|
Interoperability | MACC-13216 | The BSOD 6B no longer occurs because the Kernel Memory Leak issue is now resolved. |
Interoperability | MACC-13196 | TACC now blocks USB or SSD devices when a policy is created to block them. |
Interoperability | MACC-11129 | When MP-CASP is enabled on Application Control, Windows now boots successfully without pausing at the boot screen. |
Fixes to features | MACC-11953 | Renaming of directory paths is no longer permitted once the update mode has ended. |