Last Updated: August 5, 2026
Contents:
Policy Auditor 6.5.11 Release Notes
Policy Auditor 6.5.11 release includes security fixes and resolved issues.
Release details
For release date and build number details of 6.5.x, see KB72961.
Rating
The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.
What's new
Upgraded the OpenSSL version to 3.5.7
Upgraded libexpat from version 2.6.4 to 2.8.1
Upgraded zlib from version 1.3.1 to 1.3.2
Upgraded Axis library from version 1.4 to Axis2-1.8.0
Upgraded Apache Commons-Lang 2.3 library with the Commons-Lang 3 version. This upgrade resolve known vulnerabilities, ensuring the product aligns with current security standards.
Note
Trellix Policy Auditor version 6.5.11.106 is supported on Trellix ePO - On-prem 5.10 Service Pack 1 Update 3 or later.
Resolved issues
This release provides resolution for the following issues.
Security
Reference | Resolution |
|---|---|
IPA-1910 | Memory protection feature for Linux binaries are enabled in Policy Auditor. |
IPA-1969 | Fixes the static analysis issue in Policy Auditor Server code. |
IPA-1970 | Fixes the static analysis issue in Policy Auditor Agent code. |
IPA-1984 | Resolves SQL injection vulnerability from PA 6.5.10. |
IPA-1985 | Resolves Reflected cross-site scripting (XSS) vulnerability from PA 6.5.10. |
Policy Auditor Agent
Reference | Resolution |
|---|---|
IPA-1988 | Trellix Policy Auditor falsely reported compliance failures for Rule IDs v-257955 and v-257956 .shosts file checks during RHEL 9 STIG benchmark audits. |
TSMG-10132 | Fixed a data collection failure in userright_collector that prevented complete user privilege auditing. |
TSMG-10240 | Variable processing errors involving var_refs and var_checks in custom compliance checks caused inaccurate audit results. |
Policy Auditor Server
Reference | Resolution |
|---|---|
TSMG-10228 | Non-ASCII characters caused Trellix Endpoint Security AMSI to trigger false-positive Trojan detections and block command execution during Trellix Policy Auditor audits. |
Known issues
For a list of known issues in this product release, see KB89773.
Installation instructions
Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.
Important
Policy Auditor 6.5.11 supports Trellix ePO - On-prem 5.10 Service Pack 1 Update 3 or later.
If you want to reinstall the extension, select Remove policy and client task data from the Policy and task retention server settings before uninstalling the Policy Auditor extension. This will prevent old audit data from appearing on the endpoint. This is applicable only to fresh installations and not to extension upgrades. You can restore your previous settings after reinstalling the extension.
After upgrading the Policy Auditor agent to version 6.5.11, the ePO console displays event ID 2422 under client events. This is expected as the
AuditManagerServiceis forcefully terminated during the upgrade to install the new agent version.
Endpoint Operating System | Trellix ePO server version | Trellix Agent version | Supported Policy Auditor component versions |
|---|---|---|---|
Windows and Linux | 5.10 SP1 Update 3 or later | 5.7.x, 5.8.x | Policy Auditor Agent plug-in version — 6.5.11 |
Mac | 5.8.x |
Policy Auditor 6.5.10 Release Notes
Policy Auditor 6.5.10 release includes feature enhancements, security fixes and resolved issues.
Release details
For release date and build number details of 6.5.x, see KB72961.
Rating
The rating defines the urgency for installing this update.
This update is recommended for all environments. Apply this update at the earliest convenience.
New or changed
Policy Auditor Agent is compatible with IPv6 on Windows, Linux and MacOS platforms.
Upgraded the OpenSSL version to 3.4.1.
Resolved issues in 6.5.10
This release provides resolution for the following issues.
Security
Reference | Resolution |
|---|---|
IPA-1969 | Fixes the static analysis issue in Policy Auditor Server code. |
IPA-1970 | Fixes the static analysis issue in Policy Auditor Agent code. |
IPA-1971 | Upgrades the OpenSSL library to version 3.4.1 and the Expat library to version 2.6.4. |
IPA-1972 | Upgrades the Xerces library to version 3.3.0 and the DBus library to version 1.14.10. |
IPA-1981 | Compiler flags are added for third-party libraries in Policy Auditor for Windows. |
TSMG-9841 | Fixes the vulnerability in OpenSSL which resolves CVE-2024-6119. |
Policy Auditor Agent
Reference | Resolution |
|---|---|
IPA-1963 | Fixes the issue in the Policy Auditor Audit Engine where object collection did not complete for RHEL STIG rules. |
TSMG-9970 | Fixes the issue in File Integrity Monitoring where a baseline event was generated for each policy enforcement. |
Policy Auditor Server
Reference | Resolution |
|---|---|
IPA-1975 | Fixes the issue with rebranding changes in the UI for the McAfee default policy. |
TSMG-9849 | Fixes the issue where orphan Policy Assignment Rules (PAR) prevent the deletion of ePO tags. |
TSMG-9854 | Fixes the issue where the File Integrity Monitor file versions comparison page was broken. |
Known issues
For a list of known issues in this product release, see KB89773.
Installation instructions
Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.
ⓘ Important
If you want to reinstall the extension, select Remove policy and client task data from the Policy and task retention server settings before uninstalling the Policy Auditor extension. This will prevent old audit data from appearing on the endpoint. This is applicable only to fresh installations and not to extension upgrades. You can restore your previous settings after reinstalling the extension.
After upgrading the Policy Auditor agent to version 6.5.10, the ePO console displays event ID
2422under client events. This is expected as theAuditManagerServiceis forcefully terminated during the upgrade to install the new agent version.
Endpoint Operating System | Trellix ePO server version | Trellix Agent version | Supported Policy Auditor component versions |
|---|---|---|---|
Windows and Linux | 5.10 | 5.7.x, 5.8.x | Policy Auditor Agent plug-in version — 6.5.10 |
Mac | 5.10 | 5.7.9, 5.8.x |
Policy Auditor 6.5.9 Release Notes
Policy Auditor 6.5.9 release includes feature enhancements, security fixes and resolved issues.
Release details
For release date and build number details of 6.5.x, see KB72961.
Rating
The rating defines the urgency for installing this update.
This update is recommended for all environments. Apply this update at the earliest convenience.
New or changed
The Policy Auditor Linux installer is now x64-bit architecture.
Upgraded the zlib libraries version to 1.3.1.
Upgraded the OpenSSL version to 3.1.6.
Removed unused tables and views from the Phenginemeta module of the Policy Auditor extension.
Resolved issues in 6.5.9
This release provides resolution for the following issues.
Security
Reference | Resolution |
|---|---|
IPA-1933 | Fixes the vulnerability issue by removing the dependency on vulnerable versions of glibc libraries. |
Policy Auditor Agent
Reference | Resolution |
|---|---|
IPA-1935 | Fixes the issue where the |
Policy Auditor Server
Reference | Resolution |
|---|---|
TSMG-9692 | Fixes the issue that prevented users from blocking audits scheduled for Saturday at midnight (12 a.m.). |
Known issues
For a list of known issues in this product release, see KB89773.
Installation instructions
Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.
If you want to reinstall the extension, select
Remove policy and client task datafrom the Policy and task retention server settings before uninstalling the Policy Auditor extension. This will prevent old audit data from appearing on the endpoint. This is applicable only to fresh installations and not to extension upgrades. You can restore your previous settings after reinstalling the extension.After upgrading the Policy Auditor agent to version 6.5.9, the ePO console displays event ID 2422 under client events. This is expected as the
AuditManagerServiceis forcefully terminated during the upgrade to install the new agent version.
Endpoint | Trellix ePO | Trellix Agent | Supported Policy Auditor component |
|---|---|---|---|
Windows and | 5.10 | 5.7.x, 5.8.x | Policy Auditor Agent plug-in version — 6.5.9 |
Mac | 5.10 | 5.7.9, 5.8.x |
Policy Auditor 6.5.8 Release Notes
Policy Auditor 6.5.8 release includes feature enhancements and resolved issues.
Release details
For release date and build number details of 6.5.x, see KB72961.
Rating
The rating defines the urgency for installing this update.
This update is recommended for all environments. Apply this update at the earliest convenience.
New or changed
Users can now select specific inventory categories during the sync scan. When inventory data is not available for syncing, a baseline scan is performed for the selected categories.
Resolved issues in 6.5.8
This release provides resolution for the following issues.
Security
Reference | Resolution |
|---|---|
IPA-1901 | Updated file permissions for world-writable files on the Linux platform. |
IPA-1905 | Fixes SQL injection in multiple web pages. |
IPA-1907 | Fixes reflected cross-site scripting (XSS) in multiple web pages. |
IPA-1908 | Fixes stored cross-site scripting (XSS) in multiple web pages. |
IPA-1914 | Upgrade Apache Xerces library version to 3.2.5 which resolves CVE-2018-1311. |
TSMG-9465 | Upgrade OpenSSL version to 3.1.4 which resolves CVE-2023-5363. |
Policy Auditor Agent
Reference | Resolution |
|---|---|
IPA-1880 | The Policy Auditor Advanced Host Assessment now performs a baseline scan if the local database is empty or not found for the selected inventory categories. |
IPA-1903 | Fixes the issue where the scheduled automated deployment reinstall Policy Auditor Agent on Mac OS platforms. |
TSMG-9395 | Fixes the issue where the scheduled automated deployment reinstall Policy Auditor Agent daily on Linux platforms. |
Policy Auditor Server
Reference | Resolution |
|---|---|
IPA-1885 | Removed dependency on VC++ 2010 Redistributable for Policy Auditor Server. |
Known issues
For a list of known issues in this product release, see KB89773.
Installation instructions
Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.
Important
If you want to reinstall the extension, select Remove policy and client task data from the Policy and task retention server settings before uninstalling the Policy Auditor extension. This will prevent old audit data from appearing on the endpoint. This is applicable only to fresh installations and not to extension upgrades. You can restore your previous settings after reinstalling the extension.
Endpoint Operating System | Trellix ePO server version | Trellix Agent version | Supported Policy Auditor component versions |
|---|---|---|---|
Windows and Linux | 5.10 | 5.7.x, 5.8.x | Policy Auditor Agent plug-in version — 6.5.8 |
Mac | 5.10 | 5.7.9, 5.8.x |
Policy Auditor 6.5.7 Release Notes
Policy Auditor 6.5.7 release includes the resolved customer issues including security fixes.
Release details
For release date and build number details of 6.5.x, see KB72961.
Rating
The rating defines the urgency for installing this update.
This update is recommended for all environments. Apply this update at the earliest convenience.
New or changed
Policy Auditor Agent RPM package is now available for RHEL versions 7, 8 and 9.
Resolved issues in 6.5.7
This release provides resolution for the following issues.
Security
Reference | Resolution |
|---|---|
IPA-1865 | Upgrade Crypto++ version to 8.8 which solves CVE-2022-48570. |
TSMG-9093 | Upgrade OpenSSL version to 3.1.3 which solves CVE-2023-3817 and CVE-2023-2975. |
Policy Auditor Agent
Reference | Resolution |
|---|---|
IPA-1867 | Fixes an issue where upgrading Policy Auditor Agent cleared the inventory stored in the local database of an endpoint. |
TSMG-8739 | The PA inventory scan now retrieves data from all Windows 2016 systems. |
TSMG-8743 | PA auditmanager no longer communicates with external IP addresses. |
TSMG-8891 | Fixes an issue where the PA Auditmanager service failed to start on RHEL version 7 with SELinux enabled. |
TSMG-8922 | Fixes an issue where Policy Auditor 6.5.5 failed to install on many Windows systems. |
TSMG-9015 | Fixes an issue where the PA Auditmanager service failed to start on RHEL version 9 with SELinux enabled. |
TSMG-9041 | Fixes an issue where Policy Auditor 6.5.5 failed to install on RHEL 8.7 and 8.8 versions with SELinux enabled. |
TSMG-9143 | The product version verification is now successful on RHEL with SELinux enabled. |
Known issues
For a list of known issues in this product release, see KB89773.
Installation instructions
Install Policy Auditor Agent plug-in versions that are supported in your environment.
Important
This release is only for client packages, we recommend that you use the previous version of the ePO extension.
Endpoint | Trellix ePO | Trellix Agent | Supported Policy Auditor component |
|---|---|---|---|
Windows and | 5.10 | 5.7.x, 5.8.0 | Policy Auditor Agent plug-in version — 6.5.7 |
Mac | 5.10 | 5.7.9, 5.8.0 |
Policy Auditor 6.5.6 Release Notes
Policy Auditor 6.5.6 release introduces enhancements and addresses known issues.
Release details
For release date and build number details of 6.5.x, see KB72961.
Rating
The rating defines the urgency for installing this update.
This update is recommended for all environments. Apply this update at the earliest convenience.
New or changed
This release introduces new features and enhances existing features.
A new server task PA: Tag Agents - Partial Application is introduced in this release. This server task tags agents that have reported less than 10 applications. You can set the number of applications tagged with the agent. By default, it is set to 10. For more information, see Tag Agents - Partial application under Inventory Scan.
Policy Auditor 6.5.6 is compatible with ePO 5.10.0 Service Pack 1 Update 1, which includes support for the Microsoft JDBC database driver. This enables multi-subnet failover for Policy Auditor. Before you switch to the Microsoft JDBC database driver, check if other product extensions are compatible. For details, see KB96549.
Resolved issues in 6.5.6
This release resolves known issues.
Security
Reference | Resolution |
|---|---|
IPA-1823 | OpenSSL library upgraded to version 3.1.1 to fix vulnerability. |
Policy Auditor Agent
Reference | Resolution |
|---|---|
IPA-1821 | The Policy Auditor Agent uninstallation no longer returns an access denied error. |
TSMG-8638 | Fixes an issue where the PA audit engine fail to complete DISA STIG benchmarks on some RHEL systems. |
Policy Auditor Server
Reference | Resolution |
|---|---|
TSMG-8594 | Fixes an issue where the number of endpoints without audit results was inaccurate on the Audits page. |
Known issues
For a list of known issues in this product release, see KB89773.
Installation instructions
Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.
Important
Trellix recommends deploying PA Agent on a small number of endpoints at the beginning. In order to deploy environments that can manage more than 5000 nodes, you can gradually increase the batch size for endpoints.
If PA agent fails to install on an endpoint, Trellix recommends re-initiating product deployment tasks.
Endpoint Operating System | Trellix ePO server version | Trellix Agent version | Supported Policy Auditor component versions |
|---|---|---|---|
Windows and | 5.10 | 5.7.x |
|
Mac | 5.10 | 5.7.9 |
Policy Auditor 6.5.5 Release Notes
This release includes enhancements or updates to platform support, and resolves known issues. It also addresses product rebranding changes.
Release details
For release date and build number details of 6.5.x, see KB72961.
As part of rebranding, the certificates used to sign our Mac packages have been updated.
Important
If you are using older versions of Trellix products on macOS, make sure to install or upgrade to the latest rebranded version for all the products to function normally. Upgrading any one of the products, except Trellix Agent and Trellix Policy Auditor, removes all other products that were previously installed. For more information about installing or upgrading Trellix products on macOS, see KB96485.
Rating
The rating defines the urgency for installing this update.
This update is mandatory for all environments. Failure to apply mandatory updates might result in a security breach. Mandatory updates resolve vulnerabilities that might affect product functionality and compromise security. You must apply these updates to maintain a viable and supported product.
New or changed
Rebranding changes
Product Name - AuditManager service name in services.msc is renamed to TrellixAuditManager
McAfee is renamed to Trellix in Benchmark editor, Checks catalog, Software catalog, Waivers, Queries and Reports for Policy Auditor
7 | 6.5.11 Release Notes
Note
The name variation does not impact the product functionality and performance, you can manage and operate the product as usual.
Enhanced the Audit Benchmark results in the Queries & Reports page for Policy Auditor where an administrator can now create a tag for the system that does not display any benchmark results.
Resolved issues in 6.5.5
This release resolves known issues.
Policy Auditor Agent
Reference | Resolution |
|---|---|
IPA-1698 | Fixes an issue where the install date is shown as NULL for some applications. |
IPA-1703 | Fixes an issue where incremental scan results are not generated for inventory categories such as registered extensions, system information, and operating systems. |
Policy Auditor Trellix Agent
Reference | Resolution |
|---|---|
IPA-1756 | Fixes the issue where Messagebus socket files were not cleaned when the auditmanager service was stopped and restarted. |
Policy Auditor Server
Reference | Resolution |
|---|---|
IPA-1753 | Fixes the issue where importing the SCAP1.1 benchmark throws an error. |
IPA-1761 | Fixes the issue where running an audit for the NIST benchmark results in an error. |
IPA-1772 | Fixes the issue where the Benchmark Editor Content Processor is not performing schema validation for incorrect SCAP content. |
TSMG-8326 | Fixes the issue where the all software and current software views throw an error when converting date/time from character strings. |
Benchmark Editor
Reference | Resolution |
|---|---|
TSMG-8445 | Fixes the issue where the Benchmark rule title is missing on the Benchmark page. |
TSMG-8524 | Fixes the issue where the policy catalog displays the 'Benchmark Editor multi-platform Scan Engine' policy after uploading a custom benchmark. |
Known issues
For a list of known issues in this product release, see KB89773.
Installation instructions
Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.
Important
The changes made to PA 6.5.4 in order to support ePO 5.10 Cumulative Update 14 have affected a few Trellix supplied and custom SCAP content validations. After upgrading from PA server extension 6.5.4, Trellix recommends you to reset the Audit Engine content by following these steps:
In the Master Repository, locate the Audit Engine Content package.
Click Delete.
To download the same version of Audit Engine content, check in the package to Master Repository.
You must delete any audits created for custom benchmarks and then import the custom benchmark and create an audit.
Endpoint Operating System | Trellix ePO server version | Trellix Agent version | Supported Policy Auditor component versions |
Windows and Linux | 5.10 | 5.7.x |
|
Mac | 5.10 | 5.7.9 |
Policy Auditor 6.5.4 Release Notes
This release includes enhancements or update platform support, and resolves known issues. It also addresses product rebranding changes.
Release details
For release date and build number details of 6.5.x, see KB72961.
As part of rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update/installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates.
For information on downloading and installing the certificates, see KB91697.
Rating
The rating defines the urgency for installing this update.
This update is mandatory for all environments. Failure to apply mandatory updates might result in a security breach. Mandatory updates resolve vulnerabilities that might affect product functionality and compromise security. You must apply these updates to maintain a viable and supported product.
What's new in Trellix Policy Auditor 6.5.4
This release introduces the following feature:
Rebranding changes - This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix Policy Auditor as usual. You will notice the following changes in the software:
Product Name - McAfee Policy Auditor is renamed to Trellix Policy Auditor. Features and options in Trellix Agent, prefixed with the product name will be updated iteratively.
Note
The name variation does not impact the product functionality and performance, you can manage and operate the product as usual.
Brand logo - McAfee logo is replaced with Trellix logo.
User interface - Color and typeface are updated and provide better user experience.
End User License Agreement and Copyright - The End User License Agreement and Copyright are updated as per legal requirements. Please read the agreement for details.
Supports 5.10 Cumulative Update 14.
Increase the efficiency of inventory processing in large environments for categories such as registered extensions, operating systems, services, system information, networks, and ports.
Resolved issues in 6.5.4
This release resolves known issues.
Security
Reference | Resolution |
|---|---|
IPA-1604 | Fixes the XML External Entity Injection (XXE) vulnerability. |
IPA-1606 | Fixes the incorrectly configured memory protection options for Policy Auditor Linux Agent files. |
IPA-1607 | Fixes an issue where the ASLR and Control Flow Guard values are missing when compiling Windows binary. |
IPA-1609 | Trellix Policy Auditor now fixes a local privilege escalation vulnerability. |
IPA-1615 | Unsigned binaries are now digitally signed. |
IPA-1619 | Fixes an issue where the CSRF token is not validated by the server resulting in the URLs being vulnerable to CSRF attacks. |
IPA-1707 | Fixes the Policy Auditor Agent third party library vulnerability. |
TSMG-8106 | Fixes an issue where the World-writable file was found by removing the permission for Policy Auditor Agent files. |
Policy Auditor Agent
Reference | Resolution |
|---|---|
IPA-1698 | Fixes an issue where the install date is shown as NULL for some applications. |
IPA-1703 | Fixes an issue where incremental scan results are not generated for inventory categories such as registered extensions, system information, and operating systems. |
IPA-1706 | Fixes an issue where phoenix engine process was not terminated after inventory scan completion. |
IPA-1708 | Fixes an issue where the event files generated by Policy Auditor Agent shows incorrect product version. |
TSMG-7519 | Fixes an issue with Policy Auditor Agent registry to support ATASphere program validation process. |
TSMG-8072 | Fixes an issue where File Integrity Monitoring (FIM) does not monitor all file paths during configuration. |
Server tasks
Reference | Resolution |
|---|---|
IPA-1717 | Fixes an issue where the PA: Purge Scan Data task is unable to delete data for all inventory categories. |
Database
Reference | Resolution |
|---|---|
IPA-1714 | Fixes the database connection leak in the McAfee Policy Auditor 6.5.3 server extension. |
Policy Auditor Server
Reference | Resolution |
|---|---|
IPA-1697 | Fixes an issue where the Policy Auditor extension 6.5.4 used to process inventory scan results from older Policy Auditor Agents. |
Benchmark Editor
Reference | Resolution |
|---|---|
TSMG-7609 | Fixes an issue to support multiple benchmark audits. |
Known issues
For a list of known issues in this product release, see KB89773.
Installation instructions
Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.
Important
Purge data from previous inventory scan before upgrading to 6.5.4.
Trellix recommends you to upgrade the Policy Auditor Agent software when you upgrade Policy Auditor server. Events from older Agent versions below 6.5.4 will not be processed from the server.
Process Scan Results server task begins processing results 25 minutes after the upgrade.
Run reset baseline scan once after upgrade.
Enable the Purge Scan Data server task after upgrade to view correct data in reports.
Endpoint | Trellix ePO server | Trellix Agent | Supported Policy Auditor component |
|---|---|---|---|
Windows, Macintosh | 5.10 | 5.7.x |
|