Trellix Application and Change Control 8.4.3 Windows Release Notes

Prev Next

The Trellix Application and Change Control 8.4.3 release includes enhancements and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating

The rating defines the urgency for installing this update.

This release is recommended for all environments. Apply this update at the earliest convenience.

Release details

For release dates and build numbers, see KB87944.

Upgrade support

This release supports upgrading from:

  • TACC extension 8.2.x, 8.3.0–8.3.8, 8.4.0, 8.4.1 and 8.4.2

    When you upgrade from the existing TACC extension, you must not change any existing rules and configuration until the Solidcore: Migration server task is completed. The migration task usually takes a few hours to a day, depending on the inventory data volume of your environment.

    Note

    Trellix recommends disabling General Policy enforcement before upgrading to TACC 8.4.x from any version earlier to TACC 8.4.x as it can override configuration values integrated with the extension in TACC 8.4.x to their default values. For details, see KB96798.

  • TACC client 8.2.x, 8.3.0–8.3.7, 8.4.0, 8.4.1, and 8.4.2

For information about the TACC extension and client upgrade supported path, see KB87944.

New or changed

Enhanced self-protection for TACC files—Additional self-protection mechanisms have been introduced for specific TACC files, including evt_cache, inventory, TACC log files, and the TACC service. For client configuration details, see the Client Configuration for TACC section.

Note

By default, protection is enabled for evt_cache, inventory, and the TACC service. Protection for TACC log files can be enabled as needed.

Email notification dialog for approval requests—This release introduces a new email notification dialog box for approval request events. When a user selects an approval event, the system prompts them to enter a valid email address. The Request button is enabled only after a valid email address is entered. If the user cancels, the system does not generate a request for the administrator. If the user skips, the system bypasses the email notification but still sends the request to the administrator. On submission, the system generates two XML files (rule.xml and request.xml) as part of the policy discovery flow and sends them to ePO - On-prem, where they are stored in the database. The user’s email address associated with the request is now displayed on the Policy Discovery page.

Note

Email notifications via Automatic Response in Policy Discovery are supported with ePO - On-prem 5.10 Service Pack 1 Update 5 and later.

Automatic Response configuration —The response is triggered only for Received approval requests that include a user email. Users can modify the default configuration to enable responses for Received and Not Received requests. If configured, an automatic response can be triggered regardless of the approval request status.

Note

An Automatic Response triggers only if an action is taken on the Policy Discovery page. This is supported with ePO - On-prem 5.10 Service Pack 1 Update 5 and later.

This release includes these improvements to the Approval Request system:

  • Global actions—If an Automatic Response is configured, and before the policy is applied at the endpoint, a new request is received for an already approved Policy Discovery request, an Automatic Response triggers for the new request, and the associated user email (if available) is notified.

  • Custom actions—The first time a custom action is taken on a request (if the status is Received and a user email is available), the associated users are notified. If another request for the same file/groupedReqID appears under Pending Requests, then on taking a custom action, only the user emails associated with the newly received request are notified. Users who have already been notified do not receive another notification.

Known issues

For a list of current known issues, see Application and Change Control 8.x Known Issues (KB87839) and KB87838.

Resolved issues

This release resolves known issues.

TACC extension

Category

Reference

Issue descriptiom

Interoperability

MACC-12908

Fixed an issue that prevented the import of the CPE dictionary.

Fixes to Features

MACC-13339

Fixed an issue where the seconds in the event generated time were discarded in Solidcore events.

User Interface

MACC-13553

Resolved an issue that allowed quotes to be added to the "End User Notification" message fields.

Interoperability

MACC-13351

The issue causing inconsistencies in ePO policy sharing has been resolved.

Fixes to Features

MACC-13477

Fixed an issue where the event filtering—event ID status reverted after a product extensions upgrade.

Fixes to Features

MACC-13529

Issues caused by incorrect mapping and empty MD5 checksums for binaries have been resolved.

Fixes to Features

MACC-13598

The Application Control client policy now allows the "inventoryCaseSensitivityEnabled" value to be set to 2. For details, see KB96798.

User Interface

MACC-14114

Fixed an issue where users with read-only access could not view the contents of the Exclusions tab in Solidcore.

Fixes to Features

MACC-14004

Addressed an issue where Scinvlog files were created in the System Reserved Area. For details, see 000014475.

TACC client

Category

Reference

Issue description

Security

MACC-13443

Addressed a security risk related to trusted certificates.

Installation

MACC-13444

Fixed an issue where the .bat updater did not work unless its file name consisted only of lowercase letters or numbers.

Fixes to Features

MACC-13522

The allow list file now executes as intended and no longer unexpectedly appears as unsolidified.

Security

MACC-13567

Removed expired certificates from the installation folder of Solidcore.

Performance

MACC-13570

Resolved an issue where upgrading from McAfee Solidifier to Trellix Solidifier took an extended time.

Fixes to Features

MACC-13743

Fixed an issue where an error was displayed when executing a command in version 8.4.1.

User Interface

MACC-11519

Fixed an issue where Event 42 was not output to the OS log in version 8.3.6.

Fixes to Features

MACC-14354

Fixed an issue where the SAU didn't process scripts with capital letters in the name as updaters.

Fixes to Features

MACC-14146

The Windows Sysprep process now works as expected.