<<<>>> Trend Micro Incorporated June 23, 2017 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Trend Micro(TM) Deep Discovery Director 1.1 Critical Patch - Build 1249 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Contents ========================================================== 1. Critical Patch Release Information 1.1 Issues 2. Documentation Set 3. System Requirements 4. Installation 4.1 Installing 4.2 Uninstalling 5. Post-installation Configuration 6. Known Issues 7. Release History 8. Contact Information 9. About Trend Micro 10. License Agreement ========================================================== 1. Critical Patch Release Information ======================================================================= Installing this critical patch updates the backup/restore process in Deep Discovery Director 1.1 to remove a command injection vulnerability related to exported backup files. 1.1 Issues ==================================================================== This critical patch resolves the following issue: Issue: Exported backup files do not undergo sufficient data authentication, and as a result, may allow command injection attacks. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution: This critical patch redesigns the backup/restore process to improve data authentication on exported back up files and help prevent command injection attacks. 2. Documentation Set ======================================================================= To download or view electronic versions of the documentation set for this product, go to http://docs.trendmicro.com. 3. System Requirements ======================================================================= Trend Micro recommends installing Deep Discovery Director 1.1 Build 1241 before installing this critical patch. 4. Installation ======================================================================= This section explains key steps for installing the critical patch. 4.1 Installing ==================================================================== To install: a. Open the Deep Discovery Director management console. b. Go to "Administration > Updates". c. Click "Select" and then select the "CriticalPatch-DDD-1.1.0-1249-x86_64.tgz.tar" file from the folder. d. Click "Install", and then click "OK" when a confirmation message appears. e. Clear the browser cache. 4.2 Uninstalling ==================================================================== To roll back to the previous build: a. Open the Deep Discovery Director management console. b. Go to "Administration > Updates". c. Click "Roll Back" button, and then click "OK" when a confirmation message appears. 5. Post-installation Configuration ======================================================================= After applying this critical patch, the server will not backup files that are in the old format. Trend Micro recommends running a back up task after installing this critical patch to export a backup file of the configuration settings and the database using the new format. 6. Known Issues ======================================================================= There are no known issues for this critical patch. 7. Release History ======================================================================= For more information about updates to this product, go to: http://www.trendmicro.com/download 8. Contact Information ======================================================================= A license to Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, you must renew Maintenance on an annual basis at Trend Micro's then-current Maintenance fees. Contact Trend Micro via fax, phone, and email, or visit our website to download evaluation copies of Trend Micro products. http://www.trendmicro.com/us/about-us/contact/index.html NOTE: This information is subject to change without notice. 9. About Trend Micro ======================================================================= Smart, simple, security that fits As a global leader in IT security, Trend Micro develops innovative security solutions that make the world safe for businesses and consumers to exchange digital information. Copyright 2017, Trend Micro Incorporated. All rights reserved. Trend Micro and the t-ball logo are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other marks are the trademarks or registered trademarks of their respective companies. 10. License Agreement ======================================================================= View information about your license agreement with Trend Micro at: http://www.trendmicro.com/us/about-us/legal-policies/ license-agreements Third-party licensing agreements can be viewed: - By selecting the "About" option in the application user interface - By referring to the "Legal" page of the Administrator's Guide