Policy Auditor 6.5.x Release Notes

Prev Next

Last Updated: August 5, 2026


Contents:

  1. Policy Auditor 6.5.11 Release Notes

  2. Policy Auditor 6.5.10 Release Notes

  3. Policy Auditor 6.5.9 Release Notes

  4. Policy Auditor 6.5.8 Release Notes

  5. Policy Auditor 6.5.7 Release Notes

  6. Policy Auditor 6.5.6 Release Notes

  7. Policy Auditor 6.5.5 Release Notes

  8. Policy Auditor 6.5.4 Release Notes

Policy Auditor 6.5.11 Release Notes

Policy Auditor 6.5.11 release includes security fixes and resolved issues.

Release details

For release date and build number details of 6.5.x, see KB72961.

Rating

The rating defines the urgency for installing this update. This update is recommended for all environments. Apply this update at the earliest convenience.

What's new

  • Upgraded the OpenSSL version to 3.5.7

  • Upgraded libexpat from version 2.6.4 to 2.8.1

  • Upgraded zlib from version 1.3.1 to 1.3.2

  • Upgraded Axis library from version 1.4 to Axis2-1.8.0

  • Upgraded Apache Commons-Lang 2.3 library with the Commons-Lang 3 version. This upgrade resolve known vulnerabilities, ensuring the product aligns with current security standards.

Note

Trellix Policy Auditor version 6.5.11.106 is supported on Trellix ePO - On-prem 5.10 Service Pack 1 Update 3 or later.

Resolved issues

This release provides resolution for the following issues.

Security

Reference

Resolution

IPA-1910

Memory protection feature for Linux binaries are enabled in Policy Auditor.

IPA-1969

Fixes the static analysis issue in Policy Auditor Server code.

IPA-1970

Fixes the static analysis issue in Policy Auditor Agent code.

IPA-1984

Resolves SQL injection vulnerability from PA 6.5.10.

IPA-1985

Resolves Reflected cross-site scripting (XSS) vulnerability from PA 6.5.10.

Policy Auditor Agent

Reference

Resolution

IPA-1988

Trellix Policy Auditor falsely reported compliance failures for Rule IDs v-257955 and v-257956 .shosts file checks during RHEL 9 STIG benchmark audits.

TSMG-10132

Fixed a data collection failure in userright_collector that prevented complete user privilege auditing.

TSMG-10240

Variable processing errors involving var_refs and var_checks in custom compliance checks caused inaccurate audit results.

Policy Auditor Server

Reference

Resolution

TSMG-10228

Non-ASCII characters caused Trellix Endpoint Security AMSI to trigger false-positive Trojan detections and block command execution during Trellix Policy Auditor audits.

Known issues

For a list of known issues in this product release, see KB89773.

Installation instructions

Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.

Important

Policy Auditor 6.5.11 supports Trellix ePO - On-prem 5.10 Service Pack 1 Update 3 or later.

If you want to reinstall the extension, select Remove policy and client task data from the Policy and task retention server settings before uninstalling the Policy Auditor extension. This will prevent old audit data from appearing on the endpoint. This is applicable only to fresh installations and not to extension upgrades. You can restore your previous settings after reinstalling the extension.

After upgrading the Policy Auditor agent to version 6.5.11, the ePO console displays event ID 2422 under client  events. This is expected as the AuditManagerService is forcefully terminated during the upgrade to install the new agent version.

Endpoint Operating System

Trellix ePO server version

Trellix Agent version

Supported Policy Auditor component versions

Windows and Linux

5.10 SP1 Update 3 or later

5.7.x, 5.8.x

Policy Auditor Agent plug-in version — 6.5.11

Mac

5.8.x

Policy Auditor 6.5.10 Release Notes

Policy Auditor 6.5.10 release includes feature enhancements, security fixes and resolved issues.

Release details

For release date and build number details of 6.5.x, see KB72961.

Rating

The rating defines the urgency for installing this update.

This update is recommended for all environments. Apply this update at the earliest convenience.

New or changed

  • Policy Auditor Agent is compatible with IPv6 on Windows, Linux and MacOS platforms.

  • Upgraded the OpenSSL version to 3.4.1.

Resolved issues in 6.5.10

This release provides resolution for the following issues.

Security

Reference

Resolution

IPA-1969

Fixes the static analysis issue in Policy Auditor Server code.

IPA-1970

Fixes the static analysis issue in Policy Auditor Agent code.

IPA-1971

Upgrades the OpenSSL library to version 3.4.1 and the Expat library to version 2.6.4.

IPA-1972

Upgrades the Xerces library to version 3.3.0 and the DBus library to version 1.14.10.

IPA-1981

Compiler flags are added for third-party libraries in Policy Auditor for Windows.

TSMG-9841

Fixes the vulnerability in OpenSSL which resolves CVE-2024-6119.

Policy Auditor Agent

Reference

Resolution

IPA-1963

Fixes the issue in the Policy Auditor Audit Engine where object collection did not complete for RHEL STIG rules.

TSMG-9970

Fixes the issue in File Integrity Monitoring where a baseline event was generated for each policy enforcement.

Policy Auditor Server

Reference

Resolution

IPA-1975

Fixes the issue with rebranding changes in the UI for the McAfee default policy.

TSMG-9849

Fixes the issue where orphan Policy Assignment Rules (PAR) prevent the deletion of ePO tags.

TSMG-9854

Fixes the issue where the File Integrity Monitor file versions comparison page was broken.

Known issues

For a list of known issues in this product release, see KB89773.

Installation instructions

Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.

Important

If you want to reinstall the extension, select Remove policy and client task data from the Policy and task retention server settings before uninstalling the Policy Auditor extension. This will prevent old audit data from appearing on the endpoint. This is applicable only to fresh installations and not to extension upgrades. You can restore your previous settings after reinstalling the extension.

After upgrading the Policy Auditor agent to version 6.5.10, the ePO console displays event ID 2422 under client events. This is expected as the AuditManagerService is forcefully terminated during the upgrade to install the new agent version.

Endpoint Operating System

Trellix ePO server version

Trellix Agent version

Supported Policy Auditor component versions

Windows and Linux

5.10

5.7.x, 5.8.x

Policy Auditor Agent plug-in version — 6.5.10

Mac

5.10

5.7.9, 5.8.x

Policy Auditor 6.5.9 Release Notes

Policy Auditor 6.5.9 release includes feature enhancements, security fixes and resolved issues.

Release details

For release date and build number details of 6.5.x, see KB72961.

Rating

The rating defines the urgency for installing this update.

This update is recommended for all environments. Apply this update at the earliest convenience.

New or changed

  • The Policy Auditor Linux installer is now x64-bit architecture.

  • Upgraded the zlib libraries version to 1.3.1.

  • Upgraded the OpenSSL version to 3.1.6.

  • Removed unused tables and views from the Phenginemeta module of the Policy Auditor extension.

Resolved issues in 6.5.9

This release provides resolution for the following issues.

Security

Reference

Resolution

IPA-1933

Fixes the vulnerability issue by removing the dependency on vulnerable versions of glibc libraries.

Policy Auditor Agent

Reference

Resolution

IPA-1935

Fixes the issue where the AuditManager, EngineMain, and fimcli processes crash while running STIG audit with Trellix Agent 5.8.2 on all RHEL platforms.

Policy Auditor Server

Reference

Resolution

TSMG-9692

Fixes the issue that prevented users from blocking audits scheduled for Saturday at midnight (12 a.m.).

Known issues

For a list of known issues in this product release, see KB89773.

Installation instructions

Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.

If you want to reinstall the extension, select Remove policy and client task data from the Policy and task retention server settings before uninstalling the Policy Auditor extension. This will prevent old audit data from appearing on the endpoint. This is applicable only to fresh installations and not to extension upgrades. You can restore your previous settings after reinstalling the extension.

After upgrading the Policy Auditor agent to version 6.5.9, the ePO console displays event ID 2422 under client events. This is expected as the AuditManagerService is forcefully terminated during the upgrade to install the new agent version.


Endpoint
Operating
System

Trellix ePO
server version

Trellix Agent
version

Supported Policy Auditor component
versions

Windows and
Linux

5.10

5.7.x, 5.8.x

Policy Auditor Agent plug-in version — 6.5.9

Mac

5.10

5.7.9, 5.8.x

Policy Auditor 6.5.8 Release Notes

Policy Auditor 6.5.8 release includes feature enhancements and resolved issues.

Release details

For release date and build number details of 6.5.x, see KB72961.

Rating

The rating defines the urgency for installing this update.

This update is recommended for all environments. Apply this update at the earliest convenience.

New or changed

Users can now select specific inventory categories during the sync scan. When inventory data is not available for syncing, a baseline scan is performed for the selected categories.

Resolved issues in 6.5.8

This release provides resolution for the following issues.

Security

Reference

Resolution

IPA-1901

Updated file permissions for world-writable files on the Linux platform.

IPA-1905

Fixes SQL injection in multiple web pages.

IPA-1907

Fixes reflected cross-site scripting (XSS) in multiple web pages.

IPA-1908

Fixes stored cross-site scripting (XSS) in multiple web pages.

IPA-1914

Upgrade Apache Xerces library version to 3.2.5 which resolves CVE-2018-1311.

TSMG-9465

Upgrade OpenSSL version to 3.1.4 which resolves CVE-2023-5363.

   

Policy Auditor Agent

Reference

Resolution

IPA-1880

The Policy Auditor Advanced Host Assessment now performs a baseline scan if the local database is empty or not found for the selected inventory categories.

IPA-1903

Fixes the issue where the scheduled automated deployment reinstall Policy Auditor Agent on Mac OS platforms.

TSMG-9395

Fixes the issue where the scheduled automated deployment reinstall Policy Auditor Agent daily on Linux platforms.

Policy Auditor Server

Reference

Resolution

IPA-1885

Removed dependency on VC++ 2010 Redistributable for Policy Auditor Server.

Known issues

For a list of known issues in this product release, see KB89773.

Installation instructions

Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.

Important

If you want to reinstall the extension, select Remove policy and client task data from the Policy and task retention server settings before uninstalling the Policy Auditor extension. This will prevent old audit data from appearing on the endpoint. This is applicable only to fresh installations and not to extension upgrades. You can restore your previous settings after reinstalling the extension.    

Endpoint Operating System

Trellix ePO server version

Trellix Agent version

Supported Policy Auditor component versions

Windows and Linux

5.10

5.7.x, 5.8.x

Policy Auditor Agent plug-in version — 6.5.8

Mac

5.10

5.7.9, 5.8.x

Policy Auditor 6.5.7 Release Notes

Policy Auditor 6.5.7 release includes the resolved customer issues including security fixes.

Release details

For release date and build number details of 6.5.x, see KB72961.

Rating

The rating defines the urgency for installing this update.

This update is recommended for all environments. Apply this update at the earliest convenience.

New or changed

Policy Auditor Agent RPM package is now available for RHEL versions 7, 8 and 9.

Resolved issues in 6.5.7

This release provides resolution for the following issues.

Security

Reference

Resolution

IPA-1865

Upgrade Crypto++ version to 8.8 which solves CVE-2022-48570.

TSMG-9093

Upgrade OpenSSL version to 3.1.3 which solves CVE-2023-3817 and CVE-2023-2975.

Policy Auditor Agent

Reference

Resolution

IPA-1867

Fixes an issue where upgrading Policy Auditor Agent cleared the inventory stored in the local database of an endpoint.

TSMG-8739

The PA inventory scan now retrieves data from all Windows 2016 systems.

TSMG-8743

PA auditmanager no longer communicates with external IP addresses.

TSMG-8891

Fixes an issue where the PA Auditmanager service failed to start on RHEL version 7 with SELinux enabled.

TSMG-8922

Fixes an issue where Policy Auditor 6.5.5 failed to install on many Windows systems.

TSMG-9015

Fixes an issue where the PA Auditmanager service failed to start on RHEL version 9 with SELinux enabled.

TSMG-9041
TSMG-9081

Fixes an issue where Policy Auditor 6.5.5 failed to install on RHEL 8.7 and 8.8 versions with SELinux enabled.

TSMG-9143

The product version verification is now successful on RHEL with SELinux enabled.

Known issues

For a list of known issues in this product release, see KB89773.

Installation instructions

Install Policy Auditor Agent plug-in versions that are supported in your environment.

Important

This release is only for client packages, we recommend that you use the previous version of the ePO extension.

Endpoint
Operating
System

Trellix ePO
server version

Trellix Agent
version

Supported Policy Auditor component
versions

Windows and
Linux

5.10

5.7.x, 5.8.0

Policy Auditor Agent plug-in version — 6.5.7

Mac

5.10

5.7.9, 5.8.0

Policy Auditor 6.5.6 Release Notes

Policy Auditor 6.5.6 release introduces enhancements and addresses known issues.

Release details

For release date and build number details of 6.5.x, see KB72961.

Rating

The rating defines the urgency for installing this update.

This update is recommended for all environments. Apply this update at the earliest convenience.

New or changed

This release introduces new features and enhances existing features.

  • A new server task PA: Tag Agents - Partial Application is introduced in this release. This server task tags agents that have reported less than 10 applications. You can set the number of applications tagged with the agent. By default, it is set to 10. For more information, see Tag Agents - Partial application under Inventory Scan.

  • Policy Auditor 6.5.6 is compatible with ePO 5.10.0 Service Pack 1 Update 1, which includes support for the Microsoft JDBC database driver. This enables multi-subnet failover for Policy Auditor. Before you switch to the Microsoft JDBC database driver, check if other product extensions are compatible. For details, see KB96549.

Resolved issues in 6.5.6

This release resolves known issues.

Security

Reference

Resolution

IPA-1823

OpenSSL library upgraded to version 3.1.1 to fix vulnerability.

Policy Auditor Agent

Reference

Resolution

IPA-1821

The Policy Auditor Agent uninstallation no longer returns an access denied error.

TSMG-8638

Fixes an issue where the PA audit engine fail to complete DISA STIG benchmarks on some RHEL systems.

Policy Auditor Server

Reference

Resolution

TSMG-8594

Fixes an issue where the number of endpoints without audit results was inaccurate on the Audits page.

Known issues

For a list of known issues in this product release, see KB89773.

Installation instructions

Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.

Important

  1. Trellix recommends deploying PA Agent on a small number of endpoints at the beginning. In order to deploy environments that can manage more than 5000 nodes, you can gradually increase the batch size for endpoints.

  2. If PA agent fails to install on an endpoint, Trellix recommends re-initiating product deployment tasks.

Endpoint Operating System

Trellix ePO server version

Trellix Agent version

Supported Policy Auditor component versions

Windows and
Linux

5.10

5.7.x

  • Policy Auditor server extension version — 6.5.6

  • Policy Auditor Agent plug-in version — 6.5.6

Mac

5.10

5.7.9


Policy Auditor 6.5.5 Release Notes

This release includes enhancements or updates to platform support, and resolves known issues. It also addresses product rebranding changes.

Release details

For release date and build number details of 6.5.x, see KB72961.

As part of rebranding, the certificates used to sign our Mac packages have been updated.

Important

If you are using older versions of Trellix products on macOS, make sure to install or upgrade to the latest rebranded version for all the products to function normally. Upgrading any one of the products, except Trellix Agent and Trellix Policy Auditor, removes all other products that were previously installed. For more information about installing or upgrading Trellix products on macOS, see KB96485.

Rating

The rating defines the urgency for installing this update.

This update is mandatory for all environments. Failure to apply mandatory updates might result in a security breach. Mandatory updates resolve vulnerabilities that might affect product functionality and compromise security. You must apply these updates to maintain a viable and supported product.

New or changed

  • Rebranding changes        

    • Product Name - AuditManager service name in services.msc is renamed to TrellixAuditManager

    • McAfee is renamed to Trellix in Benchmark editor, Checks catalog, Software catalog, Waivers, Queries and Reports for Policy Auditor

7 | 6.5.11 Release Notes


Note

The name variation does not impact the product functionality and performance, you can manage and operate the product as usual.

  • Enhanced the Audit Benchmark results in the Queries & Reports page for Policy Auditor where an administrator can now create a tag for the system that does not display any benchmark results.

Resolved issues in 6.5.5

This release resolves known issues.

Policy Auditor Agent

Reference

Resolution

IPA-1698

Fixes an issue where the install date is shown as NULL for some applications.

IPA-1703

Fixes an issue where incremental scan results are not generated for inventory categories such as registered extensions, system information, and operating systems.

Policy Auditor Trellix Agent

Reference

Resolution

IPA-1756

Fixes the issue where Messagebus socket files were not cleaned when the auditmanager service was stopped and restarted.

Policy Auditor Server

Reference

Resolution

IPA-1753

Fixes the issue where importing the SCAP1.1 benchmark throws an error.

IPA-1761

Fixes the issue where running an audit for the NIST benchmark results in an error.

IPA-1772

Fixes the issue where the Benchmark Editor Content Processor is not performing schema validation for incorrect SCAP content.

TSMG-8326

Fixes the issue where the all software and current software views throw an error when converting date/time from character strings.

Benchmark Editor

Reference

Resolution

TSMG-8445

Fixes the issue where the Benchmark rule title is missing on the Benchmark page.

TSMG-8524

Fixes the issue where the policy catalog displays the 'Benchmark Editor multi-platform Scan Engine' policy after uploading a custom benchmark.

Known issues

For a list of known issues in this product release, see KB89773.

Installation instructions

Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.  

Important

  • The changes made to PA 6.5.4 in order to support ePO 5.10 Cumulative Update 14 have affected a few Trellix supplied and custom SCAP content validations. After upgrading from PA server extension 6.5.4, Trellix recommends you to reset the Audit Engine content by following these steps:            

    • In the Master Repository, locate the Audit Engine Content package.

    • Click Delete.

    • To download the same version of Audit Engine content, check in the package to Master Repository.

  • You must delete any audits created for custom benchmarks and then import the custom benchmark and create an audit.

Endpoint Operating System

Trellix ePO server version

Trellix Agent version

Supported Policy Auditor component versions

Windows and Linux

5.10

5.7.x

  • Policy Auditor server extension version — 6.5.5

  • Policy Auditor Agent plug-in version — 6.5.5

Mac

5.10

5.7.9

Policy Auditor 6.5.4 Release Notes

This release includes enhancements or update platform support, and resolves known issues. It also addresses product rebranding changes.

Release details

For release date and build number details of 6.5.x, see KB72961.

As part of rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update/installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates.

For information on downloading and installing the certificates, see KB91697.

Rating

The rating defines the urgency for installing this update.

This update is mandatory for all environments. Failure to apply mandatory updates might result in a security breach. Mandatory updates resolve vulnerabilities that might affect product functionality and compromise security. You must apply these updates to maintain a viable and supported product.

What's new in Trellix Policy Auditor 6.5.4

This release introduces the following feature:

  • Rebranding changes - This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix Policy Auditor as usual. You will notice the following changes in the software:

    • Product Name - McAfee Policy Auditor is renamed to Trellix Policy Auditor. Features and options in Trellix Agent, prefixed with the product name will be updated iteratively.

Note

The name variation does not impact the product functionality and performance, you can manage and operate the product as usual.

  • Brand logo - McAfee logo is replaced with Trellix logo.

  • User interface - Color and typeface are updated and provide better user experience.

  • End User License Agreement and Copyright - The End User License Agreement and Copyright are updated as per legal requirements. Please read the agreement for details.

  • Supports 5.10 Cumulative Update 14.

  • Increase the efficiency of inventory processing in large environments for categories such as registered extensions, operating systems, services, system information, networks, and ports.

Resolved issues in 6.5.4

This release resolves known issues.

Security

Reference

Resolution

IPA-1604

Fixes the XML External Entity Injection (XXE) vulnerability.

IPA-1606

Fixes the incorrectly configured memory protection options for Policy Auditor Linux Agent files.

IPA-1607

Fixes an issue where the ASLR and Control Flow Guard values are missing when compiling Windows binary.

IPA-1609

Trellix Policy Auditor now fixes a local privilege escalation vulnerability.

IPA-1615

Unsigned binaries are now digitally signed.

IPA-1619

Fixes an issue where the CSRF token is not validated by the server resulting in the URLs being vulnerable to CSRF attacks.

IPA-1707

Fixes the Policy Auditor Agent third party library vulnerability.

TSMG-8106

Fixes an issue where the World-writable file was found by removing the permission for Policy Auditor Agent files.

Policy Auditor Agent

Reference

Resolution

IPA-1698

Fixes an issue where the install date is shown as NULL for some applications.

IPA-1703

Fixes an issue where incremental scan results are not generated for inventory categories such as registered extensions, system information, and operating systems.

IPA-1706

Fixes an issue where phoenix engine process was not terminated after inventory scan completion.

IPA-1708

Fixes an issue where the event files generated by Policy Auditor Agent shows incorrect product version.

TSMG-7519

Fixes an issue with Policy Auditor Agent registry to support ATASphere program validation process.

TSMG-8072

Fixes an issue where File Integrity Monitoring (FIM) does not monitor all file paths during configuration.

Server tasks

Reference

Resolution

IPA-1717

Fixes an issue where the PA: Purge Scan Data task is unable to delete data for all inventory categories.

Database

Reference

Resolution

IPA-1714

Fixes the database connection leak in the McAfee Policy Auditor 6.5.3 server extension.

Policy Auditor Server

Reference

Resolution

IPA-1697

Fixes an issue where the Policy Auditor extension 6.5.4 used to process inventory scan results from older Policy Auditor Agents.

Benchmark Editor

Reference

Resolution

TSMG-7609

Fixes an issue to support multiple benchmark audits.

Known issues

For a list of known issues in this product release, see KB89773.

Installation instructions

Install Policy Auditor server extension and agent plug-in versions that are supported in your environment.

Important

  • Purge data from previous inventory scan before upgrading to 6.5.4.

  • Trellix recommends you to upgrade the Policy Auditor Agent software when you upgrade Policy Auditor server. Events from older Agent versions below 6.5.4 will not be processed from the server.

  • Process Scan Results server task begins processing results 25 minutes after the upgrade.

  • Run reset baseline scan once after upgrade.

  • Enable the Purge Scan Data server task after upgrade to view correct data in reports.

Endpoint
Operating System

Trellix ePO server
version

Trellix Agent
version

Supported Policy Auditor component
versions

Windows, Macintosh
and Linux

5.10

5.7.x

  • Policy Auditor server extension version — 6.5.4

  • Policy Auditor Agent plug-in version — 6.5.4