The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix Data Loss Prevention Endpoint for Windows 11.10 Update 1 (11.10.100) Release Notes

Prev Next

The Trellix DLP Endpoint for Windows 11.10 Update 1 release includes new features and resolved issues.

Product rebranding changes

This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix DLP Endpoint as usual. You will notice McAfeeDLPAgentService is renamed as TrellixDLPAgentService.

Release details

Release date - April 27, 2023

Release builds:

  • Trellix Data Loss Prevention Endpoint client build 11.10.100.17

  • Trellix Data Loss Prevention extension build 11.10.6.11

Important

We are aware of a BSoD issue with Intel 11th Gen CPUs. It is recommended not to deploy Trellix DLP Endpoint v11.9.0 to these specific systems until the issue is fixed. For more information, see KB95295.

Note

Trellix DLP Endpoint 11.10 Update 1 (11.10.100) requires Trellix DLP 11.10.6.11 extension. Trellix DLP Endpoint 11.10 Update 1 (11.10.100) client software is not compatible with earlier versions of Trellix DLP extensions.

For the specific build numbers, see Product release information in KB68147.

Note

Release to Support (RTS) releases are limited-availability releases intended for customers known to have issues resolved in the release. To align our release process with that of other Trellix product releases, the Trellix DLP team recommends that these packages should only be installed in lab environments or in limited numbers of production systems for verification of the fixes and making sure that there are no unexpected errors. Trellix does not recommend widely deploying RTS packages in production environments.

Note

Pre-Release or Beta builds are highly restricted releases that have been through partial / essential testing only. Such releases are intended for customers who have agreed to partner with us on the testing process in a more detailed and collaborative way to facilitate early access and a greater level of testing and feedback. These packages should only be installed in lab environments or on a limited number of endpoint systems in production environments. It is not recommended to use Trellix ePO - On-prem or other management tools, unless within a lab environment. To make sure that usage does not extend beyond these terms, Trellix also recommends these packages to be tightly controlled and not distributed to individuals other than those working directly with Trellix.

Data Loss Prevention (DLP) feature release

Trellix DLP 11.10.0 is a feature release version. New features, which include customer-raised product ideas are added only to the feature release versions. The most recent Long-Term Support release version of Trellix DLP Endpoint is 11.6.600. As such, version 11.10.0 doesn't end support for any previous release.

For more information about different kinds of releases, see KB91807.

Data Loss Prevention (DLP) Long-Term Support Release

Important - Trellix is enhancing its Trellix DLP release process. Each release is defined as either a Long-Term Support release or Feature Release. Feature release introduces new features. Long-Term Support (LTS) release allows customers (under tight change control) to maintain a stable Trellix DLP version without changes to functionality and existing features. The LTS release will include only security updates, bug fixes, and some optimization for the existing features using patches or hotfixes. These releases will continue to be fully installable packages.

Note

The LTS latest release for Trellix DLP Endpoint is version 11.10.100 (11.10 Update 1) to ensure high quality before becoming the stable LTS build.

For more information about LTS releases, see KB91807.

Upgrade paths not supported

Upgrade from 11.6.700, 11.9.0, 11.9.100, 11.10.0 to 11.10.100 is not supported if you are running Windows 7 service pack 1, Windows 2012 R2, or Windows 8.1. However, you can still install Trellix DLP Endpoint 11.10.100 for the first time on Windows 7 service pack 1, Windows 2012 R2, or Windows 8.1.

Important

Installing Trellix DLP Endpoint 11.10.100 for the first time on Windows 7 requires the SHA-2 code signing support update, You can learn more about SHA-2 code signing support update at Microsoft support.

Updated platform, environment, or operating system support

For additional information on supported platforms, environments, and operating systems, see KB68147.

New or changed features

This release introduces new features or improves existing features:

Classification grouping

Classification grouping enables you to construct multiple conditions based on your needs by using AND or OR operations. The previous version only enabled creating homogeneous rules, which resulted in creation of complicated and repeated rules. The current approach helps you establish a simpler and more diverse collection of Boolean rule sets. For example, you can write a custom rule that looks like ((1 AND 2) or (1 AND 3)), 1 AND (2 or 3) AND 4, and many more.

Label Info Stream support

Supports reading new Microsoft Information Protection (MIP) label information or metadata in co-auth enabled document.

Microsoft Authentication Library (MSAL) support

Microsoft Information Protection (MIP) labels version 1.12.61 use Microsoft Authentication Library (MSAL) for authentication, which requires Microsoft .NET Framework 4.7.2. or higher.

Reintroduction of support for operating systems

Trellix DLP Endpoint now supports installation on Windows 7 service pack 1, Windows 2012 R2, or Windows 8.1.

Removed feature

Seclore RMS integration with DLP Endpoint has been removed as Seclore no longer supports the SDK used for integration. For more information, see KB96499

Installation instructions

A fresh installation or upgrade of Trellix DLP Endpoint requires the Microsoft .NET Framework 4.7.2 or higher as a pre-requisite. For information about installing or upgrading Trellix Data Loss Prevention Endpoint 11.10.x software, see the Trellix Data Loss Prevention Endpoint 11.10.x Installation Guide.

Known issues

For a list of current known issues, see: Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).

Resolved issues

This update resolves known issues.

For the DLP Extension related resolved issues, see the  Trellix Data Loss Prevention Extension 11.10.6 Release Notes.

Vulnerability issues

Reference

Resolution

CVE-2023-0286

SB10395

This release fixes a type confusion vulnerability in which the public structure definition for GENERAL_NAME incorrectly specified the type x400 address field as ASN1_TYPE. For more information about vulnerability and remediation, see SB10395

CVE-2022-4304

SB10395

This release fixes a vulnerability in Open SSL RSA decryption that was caused by an improper timing-based side channel. For more information about vulnerability and remediation, see SB10395

CVE-2023-0215

SB10395

Fixed a vulnerability issue with the PEM_read_bio_ex() function, which reads a Privacy Enhanced Mail (PEM) file and returns a failure code, but still populates the name, header, and payload information. For more information about vulnerability and remediation, see SB10395

CVE-2022-4450

SB10395

Fixed a vulnerability with the public-facing API function BIO_new_NDEF. For more information about vulnerability and remediation, see SB10395



Resolved issues

Reference

Resolution

DLPW-7497, DLPW-8797

This release improves the performance of an endpoint system by updating the algorithms used in Trellix DLP Endpoint.

DLPW-7728

Fixed an issue where the Exceptions defined for manually classified .msg files did not execute for Web Protection Rules.

DLPW-7737

Fixed an issue where the HdlpDiag tool reported Trellix Agent status as disconnected, when the policy size was beyond 20Mb.

DLPW-8075

Resolved a file upload issue by adding %OpticalDrive% to the beginning of the file path in ignored processes.

DLPW-8138

Fixed an issue where Trellix DLP automatically installed Microsoft Visual C++ 2010 as a prerequisite.

DLPW-8191

Fixed an issue where Trellix DLP failed to block a concatenated ZIP and JPEG files containing sensitive Information.

DLPW-8192

Fixed an issue where delays were seen when accessing data from network shares.

DLPW-8250

Fixed an issue where Trellix DLP Endpoint could not block the printing of PDF when custom document properties are used in the classifications.

DLPW-8296

This fix prevents copying sensitive content from PowerShell.exe and cmd.exe to Notepad.

DLPW-8310

Fixed an issue where True File Type classification prevented .mov files from being transferred to a removable storage devices.

DLPW-9713

Fixed an issue with Trellix DLP Endpoint version 11.10.0 that caused some files to disappear from the My Documents folder in rare circumstances.