1. Critical Patch Release Information

Resolved Known Issues

This Critical Patch resolves the following issue(s):

Issue 1 (pct-41509), (pct-41287),

A issue may prevent the system from updating Trend Micro Apex One Security Agents from Build 8378 to 12994.

Solution

This Critical Patch updates the Trend Micro Apex One Security Agent program to resolve this issue.

Issue 2 (pct-35762),

Users may not be able to import file hash exceptions in a CSV file for Behavior Monitoring using the web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue 3 (pct-41398),

After configure the “Scan Exclusions” on Security Agent endpoints, some settings are changed unexpectedly.

Solution

This Critical Patch updates the Apex One server and Security Agent programs to resolve this issue.

Enhancements

The following enhancements are included in this Critical Patch:

Enhancement 1 (pct-41764),

This Critical Patch updates the import and export feature for firewall configuration settings in Trend Micro Apex One to enhance user experience.

Enhancement 2 (VRTSJIRACLOUD-12329),

This Critical Patch updates the related modules in Trend Micro Apex One to protect against the Damage Cleanup Engine Link Following Local Privilege Escalation Vulnerability (ZDI-CAN-23995)(CVSS 3.0, Score 7.8).

Enhancement 3 (VRTSJIRACLOUD-12554),

This Critical Patch updates the related modules in Trend Micro Apex One to protect against the Trend Micro Apex One Security Agent Link Following Local Privilege Escalation Vulnerability (ZDI-CAN-24557)(CVSS 3.0, Score 7.8).

Files Included in This Release

There are no files included in this Critical Patch release.

2. Documentation Set

To download or view electronic versions of the documentation set for this product, go to http://docs.trendmicro.com

  • Online Help: The Online Help contains an overview of features and key concepts, and information on configuring and maintaining the product.


To access the Online Help, go to http://docs.trendmicro.com

  • Installation Guide (IG): The Installation Guide contains information on requirements and procedures for installing and deploying the product.
  • Administrator's Guide (AG): The Administrator's Guide contains an overview of features and key concepts, and information on configuring and maintaining the product.
  • Getting Started Guide (GSG): The Getting Started Guide contains product overview, installation planning, installation and configuration instructions, and basic information intended to get the product 'up and running'.
  • Support Portal: The Support Portal contains information on troubleshooting and resolving known issues.
  • To access the Support Portal, go to http://success.trendmicro.com

3. System Requirements

  • Apex One Service Pack 1 supports the following web browsers:
    • Microsoft™ Internet Explorer™ 11
    • Microsoft™ Edge™
    • Google™ Chrome™
  • The Apex One Security Agent can be installed on endpoints running Microsoft Windows platforms. The Security Agent is also compatible with various third-party products.
    Visit the following website for a complete list of system requirements and compatible third-party products:
    https://docs.trendmicro.com/en-us/enterprise/apex-one.aspx
    Size of Deployment Package
    Note: All of the following deployment package sizes are for packages that do not include the Data Protection feature.
    For the fully-functional Security Agent MSI Setup Package:
    • 32-bit Setup Package (Smart Scan) = 313 MB
    • 64-bit Setup Package (Smart Scan) = 404 MB
    For the coexist Security Agent MSI Setup Package:
    • 32-bit Setup Package (Smart Scan) = 313 MB
    • 64-bit Setup Package (Smart Scan) = 404 MB
    Visit the following website for a complete list of system requirements:
    https://docs.trendmicro.com/en-us/enterprise/apex-one.aspx

4. Installation

Installing

To install:

  1. Copy the Patch executable file to a temporary folder on the server, for example, "C:\temp".
  2. Double-click the file. The modules are automatically copied to the correct destination.

This Patch installation package automatically rolls back the Apex One server to its previous configuration if there are problems during installation. If you encounter problems after installation, do a manual rollback.

Note: Azure Code Signing (ACS) Certificate Integrity Checking Enhancement for Trend Micro Apex One. For more detail, refer to https://success.trendmicro.com/dcx/s/solution/000292595?language=en_US


Uninstalling

To manually roll back to the previous build:

  1. Locate the backup folder that the Patch package created in the "\PCCSRV\Backup\Patch3_B13122" directory.
  2. Stop the Apex One Master Service.
  3. Stop "LogServer.exe" to disable debugging mode if "LogServer.exe" is running at this time.
  4. Stop the Apex One Apex Central Agent Service.
  5. Stop the Apex One Plug-in Manager Service.
  6. Stop the World Wide Web Publishing Service.*
  7. To roll back to a build earlier than Build 12380, delete the "\PCCSRV\Web\Service\ProdCfgUploader" folder.
  8. Back up the "libSQLDatabaseUpgrade.dll" and "oscedbt.exe" files under the "\PCCSRV\Admin\Utility\SQL" folder.
  9. Copy the backup modules to the original folders.
  10. Restore the backup "libSQLDatabaseUpgrade.dll" and "oscedbt.exe" files to the "\PCCSRV\Admin\Utility\SQL" folder. The file version of "libSQLDatabaseUpgrade.dll" and "oscedbt.exe" is "14.0.0.13122".
  11. Open a command prompt using an account with administrator privileges, and navigate to the "PCCSRV\Admin\Utility\SQL" folder of the Apex One server installation directory.
  12. Run the "UpgradeSQLSchema.bat" file.
  13. Locate the backup folder in the "\PCCSRV\Backup" directory.
  14. Open a command prompt using an account with administrator privileges, and navigate to the "PCCSRV\Backup" folder of the Apex One server installation directory.
  15. Run the following command in a single line: reg.exe restore HKLM\SOFTWARE\Wow6432Node\TrendMicro\OfficeScan\service RegBak_Patch3_B13122.reg
  16. Execute the following commands to check restored version and build number of Apex One server.
  • reg.exe query HKLM\SOFTWARE\Wow6432Node\TrendMicro\OfficeScan\service\Information /v Server_Version
  • reg.exe query HKLM\SOFTWARE\Wow6432Node\TrendMicro\OfficeScan\service\Information /v Server_Build
  1. Execute the following command to update version information of Apex One server for uninstallation to restored one.
  • reg.exe add HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E0CA6191-52E8-41E0-96B2-05EA08E6869C} /v DisplayVersion /d "<Server_Version>.<Server_Build>"
  1. Start the World Wide Web Publishing Service.
  2. Start the Apex One Plug-in Manager Service.
  3. Start the Apex One Apex Central Agent Service.
  4. Start the Apex One Master Service.

5. Post-installation Configuration

  1. If Data Loss Prevention forensic data is collected, before the installation, manually back up the following forensic folder and database, restore the files to the same location after the upgrade process is complete.

    • <Apex One server installation folder>\PCCSRV\Private\DLPForensicData
    • <Apex One server installation folder>\PCCSRV\Private\DLPForensicDataTracker.db
  2. Trend Micro has decided to retire the "Scan Network Drive" option under Real-time Scan settings. This setting will be removed from the product server and agent side user interface. For more detail, refer to https://success.trendmicro.com/dcx/s/solution/000290827?language=en_US

6. Known Issues

Known issues in this release:

Known issue 1

Upgrade may fail if using an MSI package to upgrade an Apex One security agent that was originally installed also using an MSI package. Perform the following steps:

  1. Ensure that the new MSI package has the same file name as the original package. If you do not know the file name of the original MSI package, check the following registry key: HKEY_CLASSES_ROOT\Installer\Products\1EFA14817AB44D447800A6FC68A0E81D\SourceList\PackageName
  2. Install the new MSI package. Use command prompt to execute the package with the parameter "/fvo". For example, msiexec /fvo c:\temp\package.msi
Known issue 2

The custom certificate is replaced with a self-signed certificate after upgrading to Apex One SP1. Perform the following steps to revert to using the original certificate:

  1. Before upgrading to Apex One SP1, manually back up the certificate file.
  2. After the upgrade process is complete, re-associate the backed-up certificate to Apex One
Known issue 3

After upgrade to Sp1 , that Smart Protection Services for scheduled update setting back to default value(Every 15 minutes).

  1. If when to change setting, please login Apex One Web console > "Administration" > "Smart Protection" > "Integrated Server" > "Update Settings" - "Update Schedule" - "Enable scheduled updates" - "Hourly" / "Every 15 minutes"
Known issue 4

A time zone issue may cause the system to display different log generation time information in the web console. In the web console, the system displays the log generation time in the time zone of the Apex One server.

  • The Apex One server stores the log generation time information in GMT+0.
  • The Security Agent sends the log generation time information (GMT+0 or local time) to the Apex One server.

7. Release History

Prior Hotfixes

Only this Critical Patch was tested for this release. Prior hotfixes were tested at the time of their release.
Issue Patch 13122 (pct-21727),

After upgrading to Build 14.0.12902, agent update may not be successful with the event message "Unable to connect to the Server".

Solution

This Hotfix updates the Trend Micro Apex One Security Agent program to resolve this issue.

Issue Patch 13122 (acc-1377),

Clicking the number on the notification pop-up screen may not display the related log information on Security Agent endpoints.

Solution

This Patch updates the Trend Micro Apex One Security Agent program to resolve this issue.

Issue Patch 13122 (acc-5462),

The system does not display the help content when clicking the help button in the Security Agent console.

Solution

This Patch updates the Trend Micro Apex One Security Agent program to resolve this issue.

Issue Patch 13122 (acc-5357),

The system does not display the related information when clicking a threat link on the Top Ransomware Detections widget.

Solution

This Patch updates the Trend Micro Apex One server program to resolve this issue.

Issue Patch 13122 (acc-2510),

An issue related to the Predictive Machine Learning feature may result in insufficient disk space on Security Agent endpoints.

Solution

This Patch updates the Trend Micro Apex One Security Agent program to resolve this issue.

Issue Patch 13122 (pct-14642),

An issue related to the Security Agent processes may cause the system to be unresponsive.

Solution

This Patch updates the Trend Micro Apex One Security Agent program to resolve this issue.

Issue Patch 13122 (pct-23173),

An issue related to the Data Loss Prevention feature may cause the system to display incorrect log information for detected email messages with an empty subject in the web console.

Solution

This Patch updates the Trend Micro Apex One Security Agent program to resolve this issue.

Issue Patch 13122 (pct-30950),

An issue related to special characters in the log content prevents the system from displaying Data Loss Prevention (DLP) logs properly in the web console.

Solution

This Patch updates the Data Loss Prevention (DLP) log query feature to resolve this issue.

Issue Patch 13122 (pct-33328),

After updating to build 12952 or later, the system is unable to deploy Anti Threat Toolkit (ATTK) using ToolBox.

Solution

This Patch updates the Trend Micro Apex One server program to resolve this issue.

Issue Patch 13122 (pct-34929),

After executing the command "pccntmon.exe -m", the system may not uninstall the Trend Micro Security Agent program on endpoints.

Solution

This Patch updates the Trend Micro Apex One Security Agent program to resolve this issue.

Issue Patch 13122 (pct-34761),

The Real-time Scan service may be stopped unexpectedly on Security Agent endpoints.

Solution

This Patch updates the Trend Micro Apex One Security Agent program to resolve this issue.

Issue Patch 13122 (pct-36453),

Depending on the "Scan network drives" setting for Manual Scan, the system may display different scan results (UNC path and mounted disk mode) in the web console.

Solution

This Patch updates the Trend Micro Apex One Security Agent program to resolve this issue.

Issue Patch 13122 (pct-34791), (pct-34950), (pct-35147), (pct-35172), (pct-35404), (pct-36041), (pct-36093), (pct-36451), (tminternal-1286), (ACC-5897),

An issue related to the the Program Inspection Engine may prevent the system from running a third-party program ( SS1) on Apex One Security Agent endpoints.

Solution

This Hotfix updates the Program Inspection Engine to version 2.9.1176 to resolve this issue.

Enhancement Patch 13122 (acc-3836),

This Hotfix updates the Firewall Policy Exceptions screen in the web console to enhance user experience.

Enhancement Patch 13122 (pct-7633), (acc-5141),

This Patch updates the UTN-USERFirst-Object certificate to enhance system task processing.

Enhancement Patch 13122 (acc-2617),

This Patch updates the Security Agent policy configuration to enhance Apex Central integration.

Enhancement Patch 13122 (VRTSJIRACLOUD-12084), (VRTSJIRACLOUD-12662),

This Patch updates the related modules in Apex One to protect against the potential privilege escalation vulnerability (ZDI-CAN-24675)(CVSS 3.0, Score 7.8).

Enhancement Patch 13122 (pct-28629),

This Patch enhances the detection capabilities in Apex One by updating the Data Loss Prevention (DLP) templates to support WoW64 browsers.

Enhancement Patch 13122 (VRTSJIRACLOUD-12669),

This Patch updates the related modules in Apex One to protect against the LogServer Link Following Local Privilege Escalation Vulnerability (ZDI-CAN-24674)(CVSS 3.0, Score 7.8).

Enhancement Patch 13122 (VRTSJIRACLOUD-12512),

This Patch updates the related modules in Apex One to protect against the LogServer.exe Arbitrary File Creation Local Privilege Escalation Vulnerability (ZDI-CAN-24609)(CVSS 3.0, Score 7.8).

Enhancement Patch 13122 (PDGJIRA-2759),

This Hotfix updates the Apex One Security Agent program to enable agent GUID synchronization with Endpoint Basecamp.

Note: For Security Agents whose GUIDs are updated during GUID synchronization, the system automatically removes related agent logs and set the Security Agents to use the default policy settings.

Trend Micro recommends you perform the following tasks:

  • Before applying this Hotfix, back up agent logs.
  • After applying this Hotfix, re-deploy policies to this kind of Security Agents.
Issue Critical Patch 12994 (pct-35525),

An issue related signature files may cause an unsuccessful agent update.

Solution

This Critical Patch updates the related signature files to resolve this issue.

Issue Critical Patch 12994 (pct-17412),

An issue related the Data Loss Prevention file removal may cause multiple vulnerability detections for the 7-Zip component used in Apex One.

Solution

This Hotfix updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12994 (pct-23578),

The Data Loss Prevention feature may not function properly in 32-bit Google Chrome web browser.

Solution

This Hotfix updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12980 (pct-18822),

The Predefined Keyword Lists for Data Loss Prevention (DLP) in the web console do not match the description in the product documentation.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12980 (pct-17724),

An unsuccessful SQL connection check prevents the system from installing Apex One Patch 12932.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12980 (pct-23427),

Related Predictive Machine Learning logs do not display in log queries in the Apex Central web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12980 (pct-15334),

Clicking the help link in some web console pages does not display the help content.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12980 (pct-24077),

An issue related to tmcomm.sys may cause the Security Agent endpoint to stop responding.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Procedure

  1. Install this Critical Patch (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder of the Apex One server installation directory using a text editor.
  3. Under the "Global Setting" section, manually add the following key and set its value to "0".
  • [Global Setting]
    • WatchDogSPLog=0
  1. Save the changes and close the file.
  2. Open the Apex One web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to Security Agents. The Apex One server deploys the command to Security Agents and adds the following registry entry on all Security Agent endpoints:
  • Path:

    • 32bit: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.
    • 64bit: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc.
  • Key: WatchDogSPLog
  • Type: DWORD
  • Value: 0

Issue Critical Patch 12980 (acc-2510),

An issue related to the Predictive Machine Learning feature may result in insufficient disk space on Security Agent endpoints.

Solution

This Patch updates the Apex One Security Agent program to resolve this issue.

Enhancement Critical Patch 12980 (acc-3225), (acc-4878),

This Critical Patch updates Data Loss Prevention (DLP) to support device control for USB tethering and Bluetooth hotspot.

Enhancement Critical Patch 12980 (pct-17053), (pct-17438), (pct-17581), (pct-13490), (pct-11562), (pct-11366),

This Critical Patch enhances the Security Agent update process to update Data Loss Prevention (DLP) templates from the Apex One server.

Enhancement Critical Patch 12980 (pct-23341),

This Critical Patch updates OpenJDK to version 11.0.22+7-LTS to enhance product security.

Issue Critical Patch 12967 (pct-19923),

After disabling and enabling the firewall on Security Agents, the firewall service may not function properly on Security Agent endpoints.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12967 (pct-19475),

After configuring exceptions for Behavior Monitoring on the web console, the system may automatically remove one or more user-defined exceptions on the Security Agent console.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12967 (pct-17951),

The system does not generate an event log for certificate import actions in the web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12967 (pct-20081),

An issue related to the update process may prevent Security Agents from synchronizing suspicious object lists from Apex Central.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12967 (pct-18950),

The system may not display the correct number of threat types on the Dashboard in the web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12967 (pct-18343),

The system does not display the related log entries when users click the "Unknown threats detection" link for Behavior Monitoring on the Dashboard in the web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12967 (pct-21898),

Users are unable to configure "Other update source" settings on the Server Update Source screen in the web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12967 (pct-3628),

After the first successful detection, Apex One Security Agent is unable to detect EICAR test files stored on a CD on subsequent attempts.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Procedure

To apply this update:

  1. Install this Critical Patch (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder of the Apex One server installation directory using a text editor.
  3. Under the "Global Setting" section, manually add the following key and set its value to "04,00".
  • [Global Setting]
  • VsapiNtkdControlFlag = 04,00
  1. Save the changes and close the file.
  2. Open the Apex One web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to Security Agents. The Apex One server deploys the command to Security Agents and adds the following registry entry on all Security Agent endpoints:
  • Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TmFilter\Parameters\
  • Key: VsapiNtkdControlFlag
  • Type: BINARY
  • Value: 04 00

Enhancement Critical Patch 12967 (VRTSJIRACLOUD-11701), (VRTSJIRACLOUD-11702),

This Critical Patch updates the Virus Scan Engine to protect against the Link Following Local Privilege Escalation security issue (ZDI-CAN-22693)(CVSS 3.0, Score 7.8).

Enhancement Critical Patch 12967 (VRTSJIRACLOUD-11557), (VRTSJIRACLOUD-11558),

This Critical Patch updates the Virus Scan Engine to protect against the Link Following Information Disclosure security issue (ZDI-CAN-22032)(CVSS 3.0, Score 4.7).

Enhancement Critical Patch 12967 (acc-2161),

This Critical Patch adds support for Attack Surface Reduction (ASR) rules in Behavior Monitoring to enhance product security capabilities.

Enhancement Critical Patch 12967 (VRTSJIRACLOUD-12006), (VRTSJIRACLOUD-12077),

This Critical Patch updates Security Agent Plug-in User Interface Manager to protect against a potential security issue (CVSS 3.0, Score 7.3).

Enhancement Critical Patch 12967 (VRTSJIRACLOUD-11896), (VRTSJIRACLOUD-11897),

This Critical Patch updates the widget component to protect against the Local File Inclusion and Remote Code Execution security issue (ZDI-CAN-23401)(CVSS 3.0, Score 7.5).

Enhancement Critical Patch 12967 (ACC-4712),

This Critical Patch updates the widget component to protect against the SQL injection security issue.

Issue Critical Patch 12952 (pct-18312),

After applying Apex One Critical Patch 12932 or 12942, users are unable to close the notification about the new Trend Vision One integration feature on the Apex One console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12952 (pct-17747),

The system does not save the configuration settings on the Smart Protection Network screen in the web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12952 (pct-17197),

The system is unable to update the Apex One Security Agent program from 14.0.9113 to 14.0.12902 on Security Agent endpoints.

Solution

This Critical Patch updates the Apex One agent program to resolve this issue.

Enhancement Critical Patch 12952 (VRTSJIRACLOUD-11568), (VRTSJIRACLOUD-11569),

This Critical Patch updates the Apex One server program to protect against a potential Local Privilege Escalation security issue.

Enhancement Critical Patch 12952 (VRTSJIRACLOUD-11102),

This Critical Patch updates the related modules in Apex One to protect against the Damage Cleanup Engine Link Following Denial-of-Service Vulnerability (ZDI-CAN-22038)(CVSS 6.1, Score 7.8).

Enhancement Critical Patch 12952 (acc-4332),

This Critical Patch updates the Virus Scan Engine (VSAPI) to support file folder protection.

Issue Critical Patch 12942 (pct-14390),

When the Securty Agent is switched to standalone mode, the change is not displayed on the Apex One server dashboard.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12942 (pct-13786),

When the operating system starts, the Apex One NT firewall is not ready.

Solution

This Critical Patch updates the Apex One agent program to resolve this issue.

Issue Critical Patch 12942 (pct-12949),

In the Apex One server console, agent management search results return unexpected results.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12942 (pct-13638),

The Apex One server cannot use the message transfer agent (MTA) to send notifications.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12942 (pct-14836),

The system does not change the agent status to "Unreachable/Offline" after the hearbeat timeout is reached.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Enhancement Critical Patch 12942 (VRTSJIRACLOUD-11495), (VRTSJIRACLOUD-11496), (ACC-3134),

This Critical Patch updates the Apex One Security Agent program to protect against a potential Local Privilege Escalation security issue (ZDI-CAN-22481)(CVSS 3.0, Score 7.8).

Enhancement Critical Patch 12942 (pct-12415),

This Critical Patch enhances the Security Agent update process to update Data Loss Prevention (DLP) templates from the Apex One server.

Issue Critical Patch 12932 (pct-4794),

A issue related to the network monitoring feature in Apex One Security Agent may affect network connections causing web browsers to become unresponsive on endpoints.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12932 (pct-10493),

The system may not display the Last Updated information for components on the Security Agent console.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12932 (pct-10999),

The system is unable to import the exception list properly for Predictive Machine Learning.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12932 (pct-4416),

When Data Loss Prevention (DLP) is enabled, the system is unable to detect files copied to a USB drive using FileVisor on endpoints.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12932 (pct-13980),

After updating to Apex One Service Pack 1 Patch 2, the Client Authentication Checksum (CAC) security setting cannot be enabled or disabled on the Global Agent Settings screen in the web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Enhancement Critical Patch 12932 (VRTSJIRACLOUD-11589),

This Critical Patch updates the related modules in Apex One to protect against the Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability (ZDI-CAN-22667)(CVSS 3.0, Score 7.8).

Enhancement Critical Patch 12932 (VRTSJIRACLOUD-11069),

This Critical Patch updates the PHP module in Apex One to protect against the stack buffer overflow vulnerability ( CVE-2023-3824).

Issue Patch 12902 (pct-6011),

Apex One Security Agent may not be able to scan and detect test samples using Predictive Machine Learning.

Solution

This Patch updates the Apex One Security Agent program to resolve this issue.

Issue Patch 12902 (pct-4539),

An issue related to the PccNTMon.exe process may result in an error and prevent the Security Agent from operating properly on endpoints.

Solution

This Patch updates the Apex One Security Agent program to resolve this issue.

Issue Patch 12902 (pct-1091),

When Data Loss Prevention (DLP) is enabled, the system may not apply policy settings properly on Security Agent endpoints.

Solution

This Patch updates the Apex One Security Agent program to resolve this issue.

Issue Patch 12902 (pct-6929),

Data Loss Prevention (DLP) is unable to block detected files that are bigger than 128 MB on Security Agent endpoints.

Solution

This Patch updates the Apex One Security Agent program to resolve this issue.

Issue Patch 12902 (pct-7916),

When Behavior Monitoring is enabled, an MSI activity maybe detected as an Unauthorized File Encryption event on Apex One Security Agent endpoints.

Solution

This Patch updates the Apex One Security Agent program to resolve this issue.

Issue Patch 12902 (pct-9712), (pct-9551), (pct-9556), (cpt-9540), (pct-9395),

A system issue may cause Apex One to become unresponsive.

Solution

This Patch updates the Apex One server program to resolve this issue.

Issue Patch 12902 (pct-11223),

The Apex One Master Service may stop unexpectedly after a spyware detection.

Solution

This Patch updates the Apex One server program to resolve this issue.

Issue Patch 12902 (pct-10461), (pct-10992),

An issue related to the Data Loss Prevention module in Apex One Security Agent may result in high CPU usage on Security Agent endpoints.

Solution

This Patch updates the Apex One Security Agent program to resolve this issue.

Issue Patch 12902 (pct-6510), (pct-11064),

An issue related to the TMBMSRV.exe service in Apex One may cause Security Agent endpoints to be unresponsive.

Solution

This Patch updates the Apex One Security Agent program to resolve this issue.

Enhancement Patch 12902 (VRTSJIRACLOUD-11411),

This Patch updates the related modules in Apex One to protect against the Improper Access Control Local Privilege Escalation Vulnerability (ZDI-CAN-21599)(CVSS 3.0, Score 7.8).

Enhancement Patch 12902 (VRTSJIRACLOUD-11160),

This Patch updates the modules in Apex One to protect against the potential SOCKS5 heap buffer overflow vulnerability (CVE-2023-38545)(CVSS 3.0, Score 7.8).

Enhancement Patch 12902 (acc-2621), (ACC-2641),

This Patch enhances the environment checking process for Apex One server updates.

Enhancement Patch 12902 (acc-2572),

This Patch enables the Apex One Security Agent program to support endpoints running Microsoft Windows 11 23H2.

Enhancement Patch 12902 (ACC-3033),

This Patch updates the default browser shortcut for the Apex One web console.

Enhancement Patch 12902 (PDGJIRA-2719), (tminternal-433),

This Patch enables Apex One (On-premises) to regularly update the information of managed Security Agents to the Endpoint Inventory app in Trend Vision One to enhance product integration. Note: This feature requires the installation of Apex Central Patch 8 or above.

Enhancement Patch 12902 (pct-10850),

This Patch updates the Behavior Monitoring feature in Apex One to support file hash exceptions.

Procedure

To set the system to support file hash values in the approved list successfully, complete the following steps:

  1. Install this Patch (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder of the Apex One server installation directory using a text editor.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • ENABLE_APPROVEDLIST_HASH_WITH_IMP_EXP =1
  1. Save the changes and close the file.

Issue Critical Patch 12536 (pct-7326),

On Security Agent endpoints running Windows 10, the system may take an excessive amount of time to restart or load the Windows logon screen.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12534 (pct-5007),

The system may not import all Security Agent settings properly from a .dat file.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12534 (pct-5681),

The system may not generate logs for file uploads to a cloud storage for Data Loss Prevention.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Enhancement Critical Patch 12534 (VRTS-11304),

This Critical Patch updates the related modules in Apex One to protect against the Link Following Local Privilege Escalation Vulnerability (ZDI-CAN-21346)(CVSS 3.0, Score 7.5).

Enhancement Critical Patch 12534 (VRTSJIRACLOUD-11275),

This Critical Patch updates the related modules in Apex One to protect against the Anti-Spyware Engine Link Following Local Privilege Escalation Vulnerability (ZDI-CAN-21522)(CVSS 3.0, Score 7.8).

Enhancement Critical Patch 12534 (VRTS-11281),

This Critical Patch updates the related modules in Apex One to protect against the Cross-Site Scripting Vulnerability (ZDI-CAN-21425)(CVSS 3.0, Score 7.8).

Enhancement Critical Patch 12534 (VRTS-11382),

This Critical Patch updates the related modules in Apex One to protect against the Exposed Dangerous Function Local Privilege Escalation Vulnerability (ZDI-CAN-21860)(CVSS 3.0, Score 7.8).

Enhancement Critical Patch 12534 (VRTS-11393),

This Critical Patch updates the related modules in Apex One to protect against the Updater Link Following Local Privilege Escalation Vulnerability ( ZDI-CAN-21896)(CVSS 3.0, Score 7.0).

Issue Critical Patch 12526 (pct-1055),

An internal issue may cause the system not to update the Spyware Scan Engine module in Apex One Security Agent.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12526 (SEG-188060),

During the Apex One Security Agent installation process, the system may not remove the Symantec Endpoint Protection application on endpoints.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12526 (SEG-189601),

After performing a rollback process on the Apex One server, the system does not properly revert related components on managed Security Agents to the previous versions.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12526 (SEG-191960),

Users are unable to access the web console of some managed Apex One servers from Apex Central.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12526 (SEG-190096),

Component updates may not be successful for Security Agents on Windows 2012 Server endpoints.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12526 (SEG-192631),

When the parameter EnableMoveNATClient is set to 1, the web console does not display the Security Agents in a domain that is moved.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12526 (pct-1193),

An internal issue prevents the system from updating files when the "Autopcc.exe -f" command is executed manually on Security Agent endpoints

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12526 (pct-3775), (pct-4216), (pct-4106),

After applying the Apex One B12512 update, users are unable to move agent endpoints using the drag-and-drop method in the web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12526 (pct-4230),

After applying the Apex One B12512 update, the system does not display the Product License screen properly in the web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12526 (pct-4379),

After applying the Apex One B12512 update, users are unable to save settings on the Integrated Smart Protection Server screen in the web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Enhancement Critical Patch 12526 (VRTS-9966),

This Critical Patch updates the Self-Protection module in Apex One Security Agent to enhance product security.

Enhancement Critical Patch 12526 (VRTS-9988),

This Critical Patch updates the Apex One server program to protect against the Origin Validation Error Local Privilege Escalation Vulnerability (ZDI-CAN-21366).

Enhancement Critical Patch 12526 (VRTS-9994),

This Critical Patch updates the Apex One server program to protect against the Origin Validation Error Local Privilege Escalation Vulnerability (ZDI-CAN-21367).

Enhancement Critical Patch 12526 (VRTS-9996),

This Critical Patch updates the Apex One server program to protect against the Origin Validation Error Local Privilege Escalation Vulnerability (ZDI-CAN-21368).

Enhancement Critical Patch 12526 (VRTS-9998),

This Critical Patch updates the Apex One server program to protect against the CNTAoSMgr Origin Validation Error Local Privilege Escalation Vulnerability (ZDI-CAN-21378).

Enhancement Critical Patch 12526 (VRTS-10000),

This Critical Patch updates the Apex One server program to protect against the Origin Validation Error Local Privilege Escalation Vulnerability (ZDI-CAN-21380).

Enhancement Critical Patch 12526 (VRTS-10002),

This Critical Patch updates the Apex One server program to protect against the Origin Validation Error Local Privilege Escalation Vulnerability (ZDI-CAN-21381).

Enhancement Critical Patch 12526 (VRTS-10004),

This Critical Patch updates the Apex One server program to protect against the Origin Validation Error Local Privilege Escalation Vulnerability (ZDI-CAN-21382).

Enhancement Critical Patch 12526 (VRTS-10006),

This Critical Patch updates the Apex One server program to protect against the CNTAoSMgr Origin Validation Error Local Privilege Escalation Vulnerability (ZDI-CAN-21383).

Enhancement Critical Patch 12526 (VRTS-10079),

This Critical Patch updates the Apex One server program to protect against the Origin Validation Error Local Privilege Escalation Vulnerability (ZDI-CAN-21665).

Enhancement Critical Patch 12526 (VRTS-10335),

This Critical Patch updates the Apex One server program to protect against the 7-Zip 7Z File Parsing Integer Underflow Remote Code Execution Vulnerability (CVE-2023-40481/ ZDI-23-1165).

Enhancement Critical Patch 12526 (VRTS-10337),

This Critical Patch updates the Apex One server program to protect against the 7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2023-40481).

Issue Critical Patch 12512 (SEG-184655),

The Apex One server is unable to receive virus detection log data from managed Security Agents.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12512 (SEG-185544),

A data conversion error occurs when the Security Agent tries to access a file path that is encoded in UTF-8 format.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12512 (SEG-186727),

An issue related to internal data processing may prevent the system from displaying the domain names properly in the web console.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12512 (SEG-188768),

Security Agent installed on endpoints using the Client Packager may not contain all the settings configured for the selected agent domain.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12512 (SEG-177092),

The system does not block some mobile devices on Security Agent endpoints based on the Device Control settings.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12512 (SEG-187321),

The system is unable to install the Apex One Security Agent on endpoints using the MSI package.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Enhancement Critical Patch 12512 (SEG-163458),

This Critical Patch updates the Case Diagnostic Tool (CDT) to allow the system to purge data in the AU_Temp folder and optimize storage space usage.

Enhancement Critical Patch 12512 (acc-136),

This Critical Patch updates the jQuery library in Apex One to enhance product security.

Procedure

After upgrading to this Critical Patch, Trend Micro recommends you clear the web browser cache to remove the old jQuery library and make the changes take effect immediately.

Enhancement Critical Patch 12512 (VRTS-10140),

This Critical Patch updates the related modules to enhance product security and protect against the Local File Inclusion Local Privilege Escalation Vulnerability.

Enhancement Critical Patch 12512 (acc-821), (acc-1039),

This Hotfix updates the Virus Scan Engine (VSAPI) to version 22.610.1017 to support Advanced Malware Detection for well-known and high-volume malware sample scanning.

Issue Hotfix 12401 (SEG-174226),

The Security Agent is unable to generate SHA-1 hashes for some file types.

Solution

This Hotfix updates the Apex One Security Agent program to resolve this issue.

Issue Hotfix 12401 (SEG-186760),

An Apex One server update may be unsuccessful with the error message "An error has occurred during SQL script execution".

Solution

This Hotfix updates the Apex One server program to resolve this issue.

Issue Hotfix 12401 (SEG-187184),

On the Agent Management screen in the Apex One server web console, specifying more than 15 characters in the Search for Endpoints field causes the system to generate a warning event.

Solution

This Hotfix updates the Apex One server program to resolve this issue.

Issue Hotfix 12401 (SEG-187958),

Performing an Apex One Toolbox plug-in program update may cause the plug-in program to be unresponsive.

Solution

This Hotfix updates the Apex One server program to resolve this issue.

Issue Hotfix 12401 (SEG-189104),

A typo is found on the Exception Rule screen for firewall policy configuration.

Solution

This Hotfix updates the Apex One server program to resolve this issue.

Issue Patch 12380 (SEG-172419),

An issue related to Behavior Monitoring may cause the operating system to shutdown unexpectedly.

Solution

This Patch updates the Behavior Monitoring module to resolve this issue.

Issue Patch 12380 (SEG-170321),

An issue related to the Firewall module may cause a third-party application to stop responding.

Solution

This Patch updates the Firewall module to resolve this issue.

Issue Patch 12380 (SEG-160574),

Under certain conditions, an agent update may fail.

Solution

This Patch updates the related components to resolve this issue.

Issue Patch 12380 (SEG-182035),

After upgrading the Apex One server, the "Behavior Monitoring Core Service (64-bit)" component is selected on the Scheduled Update and Manual Update screens in the web console.

Solution

This Patch updates related modules to resolve this issue.

Issue Patch 12380 (SEG-181749),

The system is unable to uninstall the Apex One Data Protection plug-in program.

Solution

This Patch updates the Apex One server program to resolve this issue.

Issue Patch 12380 (SEG-183862),

The system may not apply the specified action configured on the Suspicious Connection Settings screen in the web console.

Solution

This Patch resolves this issue.

Issue Patch 12380 (SEG-185833),

Under certain conditions, the system may remove third-party security applications on Security Agent endpoints.

Solution

This Patch updates the Apex One Security Agent program to resolve this issue.

Issue Patch 12380 (SEG-180294),

The system may not be able to perform an agent update successfully on Security Agent endpoints.

Solution

This Patch updates the Apex One Security Agent program to resolve this issue.

Issue Patch 12380 (SEG-187906), (SEG-160211),

An issue related to the Smart Scan feature may cause a Blue Screen of Death (BSOD) error on Security Agent endpoints.

Solution

This Patch updates the Apex One Security Agent program to resolve this issue.

Enhancement Patch 12380 (SEG-182131),

This Patch enables the Apex Central console to display up to five layers of Apex One domain hierarchy.

NOTE: This feature requires the installation of Apex Central Patch 5.

Procedure

After applying this Patch and Apex Central Patch 5:

  1. Open the Apex Central web console and go to the "Directories > Products" screen.
  2. Select the Apex One server and click "Tasks > Synchronize Apex One Agents and Domains > Deploy Now".

Enhancement Patch 12380 (SEG-176297),

This Patch removes the files isapiClientx64.dll and isapiClientx86.dll to enhance the Vulnerability Protection Service.

Enhancement Patch 12380 (SEG-183545),

This Patch updates the file integrity checking mechanism to enhance product security.

Enhancement Patch 12380 (SEG-183748),

This Patch enhances the Security Agent update process to update Data Loss Prevention (DLP) templates from the Apex One server.

Enhancement Patch 12380 (SEG-183755),

This Patch updates the log description for security scan operations to enhance user experience.

Enhancement Patch 12380 (SEG-186149),

This Patch enables Apex One to send server configuration information to Trend Vision One to enhance product integration.

NOTE: This feature requires the installation of Apex Central Patch 6.

Enhancement Patch 12380 (pct-13822), (acc-823),

This Patch updates Apex Central to enable Trend Vision One integration for managed Apex One servers.

NOTE: This feature requires the installation of Apex Central Patch 5 or above.

Issue Hotfix 12042 (SEG-169252),

Apex One Security Agents may not be able to disable the Print Screen function on endpoints.

Solution

This Hotfix updates the Apex One Security Agent program to resolve this issue.

Issue Hotfix 12042 (SEG-173779),

For CD/DVD drive file detections, the system generates Data Loss Prevention logs with lowercase file names.

Solution

This Hotfix updates the Apex One Security Agent program to resolve this issue.

Issue Hotfix 12042 (SEG-175448),

The system may not be able to apply Data Loss Prevention policy settings properly.

Solution

This Hotfix updates the Apex One Security Agent program to resolve this issue.

Issue Hotfix 12042 (SEG-176617),

The system may not be able to block Write access from some applications (such as Total Commander) using Device Control.

Solution

This Hotfix updates the Apex One Security Agent program to resolve this issue.

Issue Hotfix 12042 (SEG-177455),

Data Loss Prevent (DLP) is unable to detect and block Twitter messages containing specified keywords on Security Agent endpoints.

Solution

This Hotfix updates the Apex One Security Agent program to resolve this issue.

Issue Hotfix 12042 (SEG-178827),

The system is unable to block opened files on cloud storage using Data Loss Prevention.

Solution

This Hotfix updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12033 (SEG-175462),

On the Apex Central web console, the Web Reputation Endpoint Patch Pattern component status may be "outdated" even when regular component updates are performed on Apex One.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12033 (SEG-170303),

The Data Loss Prevention feature is unable to detect sensitive data that has been copied to a removable USB storage device.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

For more information, see the Knowledge Base article: Trend Micro Apex One Data Loss Prevention Issues after applying Windows Patches

Issue Critical Patch 12033 (SEG-172007),

The Data Loss Prevention feature is unable to block file transfers.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

For more information, see the Knowledge Base article: Trend Micro Apex One Data Loss Prevention Issues after applying Windows Patches

Issue Critical Patch 12033 (SEG-173478),

The Data Loss Prevention feature is unable to detect sensitive data that has been copied to a shared folder on an endpoint.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

For more information, see the Knowledge Base article: Trend Micro Apex One Data Loss Prevention Issues after applying Windows Patches

Issue Critical Patch 12033 (SEG-174473),

Accessing the Agents > Agent Installation > Browser-based screen on the Apex One web console sets the system to generate a false-positive Windows system event.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12033 (SEG-177060),

After setting the connection verification schedule to Hourly on the Agent > Connection Verification > Scheduled Verification screen, the hour drop-down list is still active.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Enhancement Critical Patch 12033 (VRTS-8844), (VRTS-9694),

This Critical Patch updates the Apex One Security Agent program to protect against potential privilege escalation vulnerabilities.

Enhancement Critical Patch 12033 (VRTS-8838),

This Critical Patch updates the component verification process in Apex One Security Agent to enhance product security.

Issue Critical Patch 12024 (SEG-162375),

After the Apex One server receives the heartbeat message from a Security Agent, the status of the Security Agent is still offline.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12024 (SEG-172581),

After configuring the Global Agent settings, the parameter "EnableWMIQuery" is 1 in the ofcscan.ini file on the Apex One server but the "EnableWMIQuery " registry key value is 0 on Security Agent endpoints.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12024 (SEG-169474),

After disabling the POP3 email scanning feature, the Apex One NT Listener service is unable to perform some file operations.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve the issue.

Issue Critical Patch 12024 (SEG-164250),

Sometimes the system may contain multiple temporary pattern files newpnt.zip.tmp and newpx64.zip.tmp that take up a significant amount of storage space.

Solution

This Critical Patch updates the Apex One server program to resolve the issue.

Issue Critical Patch 12024 (SEG-169616),

Sometimes the may generate the Windows event "Event ID: 15 Updated Trend Micro Apex One Antivirus status successfully to SECURITY_PRODUCT_STATE_ON" multiple times within a short time affecting system performance.

Solution

This Critical Patch updates the Apex One server program to resolve the issue.

Issue Critical Patch 12024 (SEG-176025),

The system may generate an excessive amount of Scan Operation Logs resulting in an increase in the Apex One database size.

Solution

This Critical Patch updates the Apex One Security Agent program to prevent the log generation issue in Apex One.

Issue Critical Patch 12024 (SEG-169832),

After initiating an update for Security Agents with outdated components on the Agent Manual Update screen, the system is unable to update the Behavior Monitoring Detection Pattern.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Enhancement Critical Patch 12024 (VRTS-8624), (VRTS-8311),

This Critical Patch updates the Apex One server program to protect against the Privilege Escalation Vulnerability for Trend Micro for Windows.

Enhancement Critical Patch 12024 (SEG-173156),

This Critical Patch updates the MSI agent installer to enhance product security.

Issue Critical Patch 12011 (SEG-164010),

The Behavior Monitoring components may not be updated in Apex One Security Agent on endpoints.

Solution

This Critical Patch updates the Apex One Security Agent program to resolve this issue.

Issue Critical Patch 12011 (SEG-164703),

Under certain conditions, the Apex One Security Agent installation process may be interrupted on endpoints.

Solution

This Critical Patch updates the Apex One server program to resolve this issue.

Issue Critical Patch 12011 (SEG-168687),

In Digital Asset Transmissions email notifications, the email subject does not show the correct user name.

Solution

This Critical Patch updates the Apex One server program the resolve this issue.

Enhancement Critical Patch 12011 (VRTS-8533), (VRTS-8500),

This Critical Patch updates the related modules in Apex One to protect against the Email Address Variable Length Buffer Overflow vulnerability (CVE-2022-3786).

Enhancement Critical Patch 12011 (VRTS-8676), (VRTS-8675),

This Critical Patch updates the Apex One Security Agent program to protect against the Time-of-Check Time-of-Use Local Privilege Escalation vulnerability (ZDI-CAN-19102).

Enhancement Critical Patch 12011 (VRTS-8709), (VRTS-8708),

This Critical Patch updates the Apex One server program to protect against the system privilege exploit security issue.

Enhancement Critical Patch 12011 (VRTS-8535), (VRTS-8502),

This Critical Patch updates the related modules in Apex One to protect against the Email Address 4-byte Buffer Overflow vulnerability (CVE-2022-3602).

Enhancement Critical Patch 12011 (VRTS-8859), (VRTS-8858),

This Critical Patch updates the Apex One Security Agent program to protect against the Time-of-Check Time-of-Use Local Privilege Escalation vulnerability (ZDI-CAN-19831).

Enhancement Critical Patch 12011 (PDGJIRA-2521), (PDGJIRA-3111), (VRTS-8693), (VRTS-8421), (VRTS-8423), (VRTS-8420), (PDGJIRA-2642), (VRTS-8422), (VRTS-8692),

This Critical Patch enables Apex One to support Client Authentication Checksum (CAC) security for server-agent communication.

Procedure

  1. Check that all managed Security Agents are updated to build version 12000 (or later).
  2. Open the Apex One web console and go to the "Agents > Global Agent Settings" screen.
  3. Click the "Network" tab,
  4. Go to the Server-Agent Communication section.
  5. Click the "Change" and "Verify versions" buttons.
  6. Click "Save".

Enhancement Critical Patch 12011 (PDGJIRA-2865), (PDGJIRA-2692), (PDGJIRA-2770), (PDGJIRA-2598), (PDGJIRA-1257),

This Critical Patch adds environment pre-checking in the Apex One server and Security Agent installation package (MSI) to support certificate integrity checking for Azure Code Signing (ACS).

Issue Hotfix 11602 (SEG-153570),

The audit log contains an excessive number of root account login events from Apex Central.

Solution

This Hotfix updates the Apex One server program to resolve this issue.

Issue Hotfix 11602 (SEG-155800),

An issue related to the Apex One service may cause endpoints to stop responding upon startup.

Solution

This Hotfix updates the Apex One server program to resolve this issue.

Issue Hotfix 11602 (SEG-157902),

On the Agent Management screen, the system may clear all associated settings for a subdomain when users move the subdomain to the root domain in the agent tree using the drag-and-drop method.

Solution

This Hotfix updates the Apex One server program to resolve this issue.

Issue Hotfix 11602 (SEG-162587),

An issue related to the Apex One service may cause the TMBMSRV.exe process to stop unexpectedly on Security Agent endpoints.

Solution

This Hotfix updates the Apex One Security Agent program to resolve this issue.

Issue Hotfix 11602 (SEG-165292),

The system may not display the detailed information on the Update Summary screen.

Solution

This Hotfix updates the Apex One server program to resolve this issue.

Issue Hotfix 11602 (SEG-167426),

The system may not display the content properly for some help pages.

Solution

This Hotfix updates the Apex One server program to resolve this issue.

Issue Hotfix 11602 (SEG-162920),

When using the Pccntmon.exe command, the system may not export the Security Agent component version information to the output file specified.

Solution

This Hotfix updates the Apex One server program to resolve this issue.

Procedure

To export the Security Agent component version information to a file, execute the following command:

Pccntmon.exe -v > C:\outputfile.txt

where "outputfile.txt" is the name of the output file specified.

Issue Hotfix 11602 (SEG-154383),

After upgrading Security Agents from OfficeScan XG, the system may not apply the approved program list properly for program inspection.

Solution

This Hotfix updates the Apex One Security Agent program to resolve this issue.

Issue Hotfix 11602 (SEG-164500),

The system is unable to block the URL "https://duckduckgo.com" that has been added to the User-Defined Suspicious Object List.

Solution

This Hotfix updates the Apex One Security Agent program and includes a configuration option to block the URL.

Procedure

To set the system to block the URL "https://duckduckgo.com" successfully, complete the following steps:

  1. Install this Hotfix (see "Installation").
  2. Open the "ofcscan.ini" file in the "\PCCSRV\" folder of the Apex One server installation directory using a text editor.
  3. Under the "Global Setting" section, manually add the following key and set its value to "1".
  • [Global Setting]
  • BlockURLSoWithoutSPS=1
  1. Save the changes and close the file.
  2. Open the Apex One web console and go to the "Agents > Global Agent Settings" screen.
  3. Click "Save" to deploy the setting to Security Agents. The Apex One server deploys the command to Security Agents and adds the following registry entry on all Security Agent endpoints:
  • Path:

    • 32bit: HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\OsceIntegrationConfiguration
    • 64bit: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\TrendMicro\PC-cillinNTCorp\CurrentVersion\OsceIntegrationConfiguration
  • Key: BlockURLSoWithoutSPS
  • Type: DWORD
  • Value: 1

Issue Hotfix 11602 (SEG-164685),

The system may not start a Scheduled Scan based on the configured schedule.

Solution

This Hotfix updates the Apex One server and Security Agent programs to resolve the issue.

Issue Service Pack 11564 (SEG-123958),

Running the Apex One Security Agent program on endpoints may cause the Refinitiv Workspace application to not function properly.

Solution

This Service Pack updates the Apex One Security Agent program to resolve this issue.

Issue Service Pack 11564 (SEG-135050),

Running the Apex One Security Agent and SentinelOne programs simultaneously on endpoints may cause the system to stop responding.

Solution

This Service Pack updates the Apex One Security Agent program to resolve this issue.

Issue Service Pack 11564 (SEG-138806),

Users can still start applications from connected USB devices that are set to read-only in Device Control.

Solution

This Service Pack updates the Apex One Security Agent program to resolve this issue.

Issue Service Pack 11564 (SEG-146205),

Enabling the Data Loss Prevention (DLP) feature may prevent USB modems from working properly.

Solution

This Service Pack updates the Apex One Security Agent program to resolve this issue.

Issue Service Pack 11564 (SEG-147802),

Data Loss Prevention (DLP) does not block CD/DVD devices with the IDE interface.

Solution

This Service Pack updates the Apex One Security Agent program to resolve this issue.

Issue Service Pack 11564 (SEG-151304),

When uploading files, the Microsoft Edge browser may become unresponsive.

Solution

This Service Pack updates the Apex One Security Agent program to resolve this issue.

Issue Service Pack 11564 (SEG-157294),

Running the Apex One Security Agent and VG Studio Max programs simultaneously on endpoints may cause the system to become unresponsive.

Solution

This Service Pack updates the Apex One Security Agent program to resolve this issue.

Issue Service Pack 11564 (SEG-157725),

After upgrading to Apex One Service Pack 1, the Trend Micro Endpoint Encryption Deployment Tool may not be able to display the Apex One Security Agent list properly.

Solution

This Service Pack updates the Apex One server program to resolve this issue.

Issue Service Pack 11564 (SEG-154143),

During the Apex One Service Pack 1 installation process, the error message "Setup program cannot connect to the website successfully." appears.

Solution

This Service Pack updates the related modules to resolve the issue.

Issue Service Pack 11564 (SEG-158217),

When performing a Security Agent upgrade using the installer created by the Agent Packager, the upgrade process may be unsuccessful and the Security Agent status is set to "Protection at risk".

Solution

This Service Pack updates the server program to resolve the issue.

Issue Service Pack 11564 (SEG-162056),

After applying Critical Patch build 11136, the system displays "N/A" for the File Reputation Services URL on the web console.

Solution

This Service Pack updates the Apex One server program to resolve this issue.

Issue Service Pack 11564 (SEG-158759),

After updating the Script Analyzer Unified Pattern file, the "File Self-Protection delete invalid file" Windows event logs are generated on agent endpoints.

Solution

This Service Pack updates the Apex One Security Agent program to resolve this issue.

Issue Service Pack 11564 (SEG-161748),

After applying Critical Patch build 11136 for Apex One servers running on Windows Server 2012 R2 and deploying policies from Apex Central, the policy status is still pending for managed Security Agents.

Solution

This Service Pack updates the Apex One server program to resolve this issue.

Issue Service Pack 11564 (SEG-162107),

After applying the previous patch update, the "Use configured Smart Protection Sources for service queries" setting is reset.

Solution

This Service Pack updates the Apex One server program to resolve this issue.

Issue Service Pack 11564 (SEG-162031),

If the Apex One server is unable to download components from the Trend Micro ActiveUpdate server, Security Agents may try to download the Program Inspection Monitoring Pattern repeatedly.

Solution

This Service Pack updates the self-signed digital signature files to resolve this issue.

Issue Service Pack 11564 (SEG-162850),

For Security Agent endpoints running on Windows 7 or Windows Server 2021 R2, an issue related to the OpenSSL 3.0 module may result in connection issues between Security Agents and Edge Relay servers.

Solution

This Service Pack updates the Apex One Security Agent program to resolve the issue.

Issue Service Pack 11564 (SEG-159135),

If users perform two file transfers in quick succession, Trend Micro Endpoint Encryption may not encrypt the second file.

Solution

This Service Pack updates the related module to resolve this issue.

Issue Service Pack 11564 (SEG-165369),

After applying Service Pack build 11561, users are not able to log into the web console when using a non-built-in administrator Windows account for database authentication.

Solution

This Service Pack updates the Apex One server program to resolve this issue.

Issue Service Pack 11564 (SEG-155642),

When Data Loss Prevention (DLP) is enabled on Apex One Security Agent endpoints, Google Chrome (version 106 or later) and Microsoft Edge (Chromium) may become unresponsive.

Solution

This Service Pack updates the Data Protection module to resolve this issue.

Enhancement Service Pack 11564 (VRTS-8194), (VRTS-8193),

This Service Pack updates the Spyware/Grayware Scan Engine to protect against the Link Following Local Privilege Escalation security issue.

Enhancement Service Pack 11564 (VRTS-8046), (VRTS-8045),

This Service Pack updates the Virus Scan Engine to protect against the Improper Access Control Local Privilege Escalation security issue.

Enhancement Service Pack 11564 (ACC-566), (SEG-159273),

This Service Pack enables SHA-256 certificate fingerprint support for server-agent communication.

Enhancement Service Pack 11564 (VRTS-8411), (VRTS-8412),

This Service Pack updates the Apex One Security Agent program to protect against the Link Following Local Privilege Escalation security issue.

Enhancement Service Pack 11564 (VRTS-6175),

This Service Pack enhances the Apex One server service command authorization to improve product security.

Enhancement Service Pack 11564 (VRTS-7033), (VRTS-7032),

This Service Pack updates the Uncontrolled Search Path Element to protect against the Local Remote Code Execution Vulnerability security issue.

Enhancement Service Pack 11564 (SEG-154530),

This Service Pack enables the Apex One Security Agent program to support Microsoft Windows 10 22H2 and Windows 11 22H2.

Enhancement Service Pack 11564 (VRTS-8439), (VRTS-8438),

This Service Pack updates the file upload process to protect against the Local Remote Code Execution Vulnerability security issue.

8. Contact Information

A license to Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, you must renew Maintenance on an annual basis at Trend Micro's then-current Maintenance fees.

Contact Trend Micro via fax, phone, and email, or visit our website to download evaluation copies of Trend Micro products.

https://www.trendmicro.com/en_us/contact.html

NOTE: This information is subject to change without notice.

9. About Trend Micro

Smart, simple, security that fits.

As a global leader in IT security, Trend Micro develops innovative security solutions that make the world safe for businesses and consumers to exchange digital information.

Copyright 2024, Trend Micro Incorporated. All rights reserved.

Trend Micro, the t-ball logo, OfficeScan, Trend Micro Security (for Mac), Control Manager, Trend Micro Apex One, and Trend Micro Apex Central are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other product or company names may be trademarks or registered trademarks of their owners.

10. License Agreement

View information about your license agreement with Trend Micro at: https://www.trendmicro.com/en_us/about/legal.html

Third-party licensing agreements can be viewed:

  • By selecting the "About" option in the application user interface
  • By referring to the "Legal" page of the Administrator's Guide
Back to Top