The Trellix Application and Change Control 8.4.3 release includes enhancements and resolved issues.
Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Rating
The rating defines the urgency for installing this update.
This release is recommended for all environments. Apply this update at the earliest convenience.
Release details
For release dates and build numbers, see KB87944.
Upgrade support
This release supports upgrading from:
TACC extension 8.2.x, 8.3.0–8.3.8, 8.4.0, 8.4.1 and 8.4.2
When you upgrade from the existing TACC extension, you must not change any existing rules and configuration until the Solidcore: Migration server task is completed. The migration task usually takes a few hours to a day, depending on the inventory data volume of your environment.
Note
Trellix recommends disabling General Policy enforcement before upgrading to TACC 8.4.x from any version earlier to TACC 8.4.x as it can override configuration values integrated with the extension in TACC 8.4.x to their default values. For details, see KB96798.
TACC client 8.2.x, 8.3.0–8.3.7, 8.4.0, 8.4.1, and 8.4.2
For information about the TACC extension and client upgrade supported path, see KB87944.
New or changed
Enhanced self-protection for TACC files—Additional self-protection mechanisms have been introduced for specific TACC files, including evt_cache, inventory, TACC log files, and the TACC service. For client configuration details, see the Client Configuration for TACC section.
Note
By default, protection is enabled for evt_cache, inventory, and the TACC service. Protection for TACC log files can be enabled as needed.
Email notification dialog for approval requests—This release introduces a new email notification dialog box for approval request events. When a user selects an approval event, the system prompts them to enter a valid email address. The Request button is enabled only after a valid email address is entered. If the user cancels, the system does not generate a request for the administrator. If the user skips, the system bypasses the email notification but still sends the request to the administrator. On submission, the system generates two XML files (rule.xml and request.xml) as part of the policy discovery flow and sends them to ePO - On-prem, where they are stored in the database. The user’s email address associated with the request is now displayed on the Policy Discovery page.
Note
Email notifications via Automatic Response in Policy Discovery are supported with ePO - On-prem 5.10 Service Pack 1 Update 5 and later.
Automatic Response configuration —The response is triggered only for Received approval requests that include a user email. Users can modify the default configuration to enable responses for Received and Not Received requests. If configured, an automatic response can be triggered regardless of the approval request status.
Note
An Automatic Response triggers only if an action is taken on the Policy Discovery page. This is supported with ePO - On-prem 5.10 Service Pack 1 Update 5 and later.
This release includes these improvements to the Approval Request system:
Global actions—If an Automatic Response is configured, and before the policy is applied at the endpoint, a new request is received for an already approved Policy Discovery request, an Automatic Response triggers for the new request, and the associated user email (if available) is notified.
Custom actions—The first time a custom action is taken on a request (if the status is Received and a user email is available), the associated users are notified. If another request for the same file/groupedReqID appears under Pending Requests, then on taking a custom action, only the user emails associated with the newly received request are notified. Users who have already been notified do not receive another notification.
Known issues
For a list of current known issues, see Application and Change Control 8.x Known Issues (KB87839) and KB87838.
Resolved issues
This release resolves known issues.
TACC extension
Category | Reference | Issue descriptiom |
|---|---|---|
Interoperability | MACC-12908 | Fixed an issue that prevented the import of the CPE dictionary. |
Fixes to Features | MACC-13339 | Fixed an issue where the seconds in the event generated time were discarded in Solidcore events. |
User Interface | MACC-13553 | Resolved an issue that allowed quotes to be added to the "End User Notification" message fields. |
Interoperability | MACC-13351 | The issue causing inconsistencies in ePO policy sharing has been resolved. |
Fixes to Features | MACC-13477 | Fixed an issue where the event filtering—event ID status reverted after a product extensions upgrade. |
Fixes to Features | MACC-13529 | Issues caused by incorrect mapping and empty MD5 checksums for binaries have been resolved. |
Fixes to Features | MACC-13598 | The Application Control client policy now allows the "inventoryCaseSensitivityEnabled" value to be set to 2. For details, see KB96798. |
User Interface | MACC-14114 | Fixed an issue where users with read-only access could not view the contents of the Exclusions tab in Solidcore. |
Fixes to Features | MACC-14004 | Addressed an issue where Scinvlog files were created in the System Reserved Area. For details, see 000014475. |
TACC client
Category | Reference | Issue description |
|---|---|---|
Security | MACC-13443 | Addressed a security risk related to trusted certificates. |
Installation | MACC-13444 | Fixed an issue where the .bat updater did not work unless its file name consisted only of lowercase letters or numbers. |
Fixes to Features | MACC-13522 | The allow list file now executes as intended and no longer unexpectedly appears as unsolidified. |
Security | MACC-13567 | Removed expired certificates from the installation folder of Solidcore. |
Performance | MACC-13570 | Resolved an issue where upgrading from McAfee Solidifier to Trellix Solidifier took an extended time. |
Fixes to Features | MACC-13743 | Fixed an issue where an error was displayed when executing a command in version 8.4.1. |
User Interface | MACC-11519 | Fixed an issue where Event 42 was not output to the OS log in version 8.3.6. |
Fixes to Features | MACC-14354 | Fixed an issue where the SAU didn't process scripts with capital letters in the name as updaters. |
Fixes to Features | MACC-14146 | The Windows Sysprep process now works as expected. |