The Trellix DLP Endpoint for Windows 11.10 Update 3 (11.10.300) release includes new features and resolved issues.
Rating for 11.10 Update 3 (11.10.300)
The rating defines the urgency for installing this update.
Mandatory
This release is mandatory for all environments. Failure to apply mandatory updates might result in a security breach. Mandatory updates resolve vulnerabilities that might affect product functionality and compromise security. You must apply these updates to maintain a viable and supported product.
For more information, see KB51560
Release details
Release date - October 3, 2024
Release builds:
Trellix Data Loss Prevention Endpoint client build 11.10.300.1432
Note
Trellix DLP Endpoint 11.10 Update 3 (11.10.300) requires Trellix DLP 11.11.3 extension. Trellix DLP Endpoint 11.10 Update 3 (11.10.300) client software is not compatible with earlier versions of Trellix DLP extensions.
For the specific build numbers, see Product release information in KB68147.
Supported upgrade path
Upgrade from... | To |
|---|---|
11.10.200 | 11.10.300 |
11.10.102.22 | 11.10.300 |
11.10.100.172 | 11.10.300 |
11.6.800 | 11.10.300 |
11.6.700 | 11.10.300 |
Updated platform, environment, or operating system support
For additional information on supported platforms, environments, and operating systems, see KB68147.
As part of our ongoing security enhancements, we have upgraded the following third-party libraries to address vulnerabilities. For detailed information on the previous versions and changes, please refer to the respective vendor Release Notes.
Libraries | Versions |
|---|---|
zlib | 1.3.1 |
KeyView | 24.3 |
Microsoft Information Protection (MIP) | 1.14.146 |
OpenSSL | 3.3.1 |
Berkeley DB | 5.3.28 |
7-Zip | 23.01 |
libde265 | 1.0.15 |
libxml2 | 2.12.5 |
Minor update or fixes
This release introduces new features or improves existing features:
Manually Resolve DFS - Using this option, you can manually resolve network share paths of all the child nodes of DFS shares and enter them individually in the network definitions. Alternatively, if you unchecked this option, Trellix DLP Endpoint resolves all child nodes' share paths of the DFS share paths mentioned in the network definition. To enable Manual DFS Share navigate to Policy Catalog → Data Loss Prevention <version> → Windows → edit a policy → Settings → Advanced Configuration.
Support for the Turkish letter ‘İ’ - Trellix DLP Endpoint for Windows now supports Turkish characters with case insensitivity for dictionary and keyword. For example, when a classification is created using a keyword containing the uppercase letter "İ", Trellix DLP converts it to the lowercase letter "i" allowing the rule to trigger.
Note
Trellix DLP Endpoint can not convert to lowercase Turkish letter "ı" Ascii character code (305). However, you can create an entry in the Dictionary tab for both "ı" Ascii character code (305) and "i" Ascii character code (105) or you can create an advance pattern to detect all "iıİ".
Application File Access Protection (AFAP) Rule enhancements - AFAP rule hooks are now injected only into processes configured for inspection in the AFAP rule, enhancing the overall performance of the product.
Resolved issues
This update resolves known issues and customer reported issues.
For the DLP Extension related resolved issues, see the Trellix Data Loss Prevention Extension 11.11.3 Release Notes.
Resolved Endpoint issues
Reference | Resolution |
|---|---|
DLPW-8631 | Fixed an issue where the Removable Storage File Access Device rule failed to block file access for CD/DVD devices even when the Device Type was set to CD/DVD and the True File Type was set to Actual File Type. |
DLPW-8867 | Fixed an issue where Trellix DLP Endpoint moved blocked files to Quarantine folder in plain text when Removable Storage Protection rule's reaction was set to . |
DLPW-10013 | Fixed an issue in Windows 11 where the Plug and Play Device rule failed to block UAS (SCSI) storage devices |
DLPW-10122 | Fixed an issue where the USB device was redirected from the host machine to the Citrix virtual machine. This allowed users to access or write to the device even when the Citrix VAD Device Rule (formerly the Citrix XenApp Rule) was applied. |
DLPW-10287 | Fixed an issue where sensitive files were not blocked when a folder containing sensitive files was dragged and dropped onto Microsoft Teams. |
DLPW-10501 | Fixed an issue where the endpoint discovery scan incorrectly identified random 16-digit numbers that did not pass the Luhn check. As a fix, checkbox is provided in → page. To use the Respect cell boundaries in spreadsheets option:
|
DLPW-10517 | Fixed an issue in which the Application File Access Protection rule failed to block files when copied to removable media. |
DLPW-10518 | Fixed an issue that caused delays when opening .txt files in a Virtual Desktop Infrastructure (VDI) environment. |
DLPW-10528 | Fixed an issue where Microsoft Outlook displayed the following error message when sending an email: "The Send operation failed because the item was deleted before it was sent". |
DLPW-11137 | Fixed an issue in which evidence files in .pdf format were automatically appended with the .txt extension. |
DLPW-11163 | An issue that prevented updating to the latest version of Trellix DLP Endpoint 11.10.x has been resolved. |
DLPW-11186 | Fixed an issue where the Plug and Play Device rule failed to block files printed via USB devices. |
DLPW-11269 | Fixed an issue where the cloud protection rule did not prevent the files from being uploaded to Microsoft OneDrive. |
DLPW-11392 | Fixed an issue where false positives were generated when the application file access protection rule was configured on Microsoft Teams. |
DLPW-11657 | Fixed a localization issue that occurred after updating Trellix DLP Endpoint to the latest version. |
DLPW-11688 | Fixed an issue where the RegDocDB.dat file in the WebDAV evidence share path was not downloading to endpoints. |
DLPW-12632 | Fixed an issue where incidents were generated for Microsoft 365 Business even if the Office 365 option was unchecked in Cloud Service settings. |
DLPW-12634 | Fixed an issue that caused the Microsoft sign-in dialog box to appear unexpectedly after updating Trellix DLP Endpoint for Windows to the latest version. |
DLPW-12773 | Fixed an issue where the web protection rule failed to block the upload of sensitive text in the body of web-based emails. |
DLPW-13679 | Fixed an issue where the IsActionTriggered value was inconsistent in the email protection rule when using a recipient threshold condition. |
DLPW-13816 | Fixed an issue where |
Known issues
For a list of current known issues, see: Trellix Data Loss Prevention 11.x.x Known Issues (KB89301).