The Trellix DLP Endpoint for Windows 11.10 Update 1 release includes new features and resolved issues.
Product rebranding changes
This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix DLP Endpoint as usual. You will notice McAfeeDLPAgentService is renamed as TrellixDLPAgentService.
Release details
Release date - April 27, 2023
Release builds:
Trellix Data Loss Prevention Endpoint client build 11.10.100.17
Trellix Data Loss Prevention extension build 11.10.6.11
Important
We are aware of a BSoD issue with Intel 11th Gen CPUs. It is recommended not to deploy Trellix DLP Endpoint v11.9.0 to these specific systems until the issue is fixed. For more information, see KB95295.
Note
Trellix DLP Endpoint 11.10 Update 1 (11.10.100) requires Trellix DLP 11.10.6.11 extension. Trellix DLP Endpoint 11.10 Update 1 (11.10.100) client software is not compatible with earlier versions of Trellix DLP extensions.
For the specific build numbers, see Product release information in KB68147.
Note
Release to Support (RTS) releases are limited-availability releases intended for customers known to have issues resolved in the release. To align our release process with that of other Trellix product releases, the Trellix DLP team recommends that these packages should only be installed in lab environments or in limited numbers of production systems for verification of the fixes and making sure that there are no unexpected errors. Trellix does not recommend widely deploying RTS packages in production environments.
Note
Pre-Release or Beta builds are highly restricted releases that have been through partial / essential testing only. Such releases are intended for customers who have agreed to partner with us on the testing process in a more detailed and collaborative way to facilitate early access and a greater level of testing and feedback. These packages should only be installed in lab environments or on a limited number of endpoint systems in production environments. It is not recommended to use Trellix ePO - On-prem or other management tools, unless within a lab environment. To make sure that usage does not extend beyond these terms, Trellix also recommends these packages to be tightly controlled and not distributed to individuals other than those working directly with Trellix.
Data Loss Prevention (DLP) feature release
Trellix DLP 11.10.0 is a feature release version. New features, which include customer-raised product ideas are added only to the feature release versions. The most recent Long-Term Support release version of Trellix DLP Endpoint is 11.6.600. As such, version 11.10.0 doesn't end support for any previous release.
For more information about different kinds of releases, see KB91807.
Data Loss Prevention (DLP) Long-Term Support Release
Important - Trellix is enhancing its Trellix DLP release process. Each release is defined as either a Long-Term Support release or Feature Release. Feature release introduces new features. Long-Term Support (LTS) release allows customers (under tight change control) to maintain a stable Trellix DLP version without changes to functionality and existing features. The LTS release will include only security updates, bug fixes, and some optimization for the existing features using patches or hotfixes. These releases will continue to be fully installable packages.
Note
The LTS latest release for Trellix DLP Endpoint is version 11.10.100 (11.10 Update 1) to ensure high quality before becoming the stable LTS build.
For more information about LTS releases, see KB91807.
Upgrade paths not supported
Upgrade from 11.6.700, 11.9.0, 11.9.100, 11.10.0 to 11.10.100 is not supported if you are running Windows 7 service pack 1, Windows 2012 R2, or Windows 8.1. However, you can still install Trellix DLP Endpoint 11.10.100 for the first time on Windows 7 service pack 1, Windows 2012 R2, or Windows 8.1.
Important
Installing Trellix DLP Endpoint 11.10.100 for the first time on Windows 7 requires the SHA-2 code signing support update, You can learn more about SHA-2 code signing support update at Microsoft support.
Updated platform, environment, or operating system support
For additional information on supported platforms, environments, and operating systems, see KB68147.
New or changed features
This release introduces new features or improves existing features:
Classification grouping
Classification grouping enables you to construct multiple conditions based on your needs by using AND or OR operations. The previous version only enabled creating homogeneous rules, which resulted in creation of complicated and repeated rules. The current approach helps you establish a simpler and more diverse collection of Boolean rule sets. For example, you can write a custom rule that looks like ((1 AND 2) or (1 AND 3)), 1 AND (2 or 3) AND 4, and many more.
Label Info Stream support
Supports reading new Microsoft Information Protection (MIP) label information or metadata in co-auth enabled document.
Microsoft Authentication Library (MSAL) support
Microsoft Information Protection (MIP) labels version 1.12.61 use Microsoft Authentication Library (MSAL) for authentication, which requires Microsoft .NET Framework 4.7.2. or higher.
Reintroduction of support for operating systems
Trellix DLP Endpoint now supports installation on Windows 7 service pack 1, Windows 2012 R2, or Windows 8.1.
Removed feature
Seclore RMS integration with DLP Endpoint has been removed as Seclore no longer supports the SDK used for integration. For more information, see KB96499
Installation instructions
A fresh installation or upgrade of Trellix DLP Endpoint requires the Microsoft .NET Framework 4.7.2 or higher as a pre-requisite. For information about installing or upgrading Trellix Data Loss Prevention Endpoint 11.10.x software, see the Trellix Data Loss Prevention Endpoint 11.10.x Installation Guide.
Known issues
For a list of current known issues, see: Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).
Resolved issues
This update resolves known issues.
For the DLP Extension related resolved issues, see the Trellix Data Loss Prevention Extension 11.10.6 Release Notes.
Vulnerability issues
Reference | Resolution |
|---|---|
CVE-2023-0286 | This release fixes a type confusion vulnerability in which the public structure definition for |
CVE-2022-4304 | This release fixes a vulnerability in Open SSL RSA decryption that was caused by an improper timing-based side channel. For more information about vulnerability and remediation, see SB10395 |
CVE-2023-0215 | Fixed a vulnerability issue with the |
CVE-2022-4450 | Fixed a vulnerability with the public-facing API function |
Resolved issues
Reference | Resolution |
|---|---|
DLPW-7497, DLPW-8797 | This release improves the performance of an endpoint system by updating the algorithms used in Trellix DLP Endpoint. |
DLPW-7728 | Fixed an issue where the Exceptions defined for manually classified .msg files did not execute for Web Protection Rules. |
DLPW-7737 | Fixed an issue where the HdlpDiag tool reported Trellix Agent status as disconnected, when the policy size was beyond 20Mb. |
DLPW-8075 | Resolved a file upload issue by adding |
DLPW-8138 | Fixed an issue where Trellix DLP automatically installed Microsoft Visual C++ 2010 as a prerequisite. |
DLPW-8191 | Fixed an issue where Trellix DLP failed to block a concatenated ZIP and JPEG files containing sensitive Information. |
DLPW-8192 | Fixed an issue where delays were seen when accessing data from network shares. |
DLPW-8250 | Fixed an issue where Trellix DLP Endpoint could not block the printing of PDF when custom document properties are used in the classifications. |
DLPW-8296 | This fix prevents copying sensitive content from PowerShell.exe and cmd.exe to Notepad. |
DLPW-8310 | Fixed an issue where True File Type classification prevented .mov files from being transferred to a removable storage devices. |
DLPW-9713 | Fixed an issue with Trellix DLP Endpoint version 11.10.0 that caused some files to disappear from the My Documents folder in rare circumstances. |