1. Hotfix Release Information

Resolved Known Issues

Trend Micro Apex Central™ as a Service

This Hotfix resolves the following issue(s):

Issue 1 (SEG-69664)

The time range setting does not work in Detail Application Control View of the Report Template.

Solution

This hotfix ensures that the time range setting works normally on the Report Template.

Issue 2 (SEG-74196)

The number of policy targets that displays on the Policy Management is incorrect because the count does not include offline Security Agents.

Solution

This hotfix updates the policy target number to display the correct value, including offline Security Agents.

Issue 3 (SEG-64007), (SEG-66447), (SEG-64333)

Apex Central does not run the deploy command even if it already downloaded new components from the ActiveUpdate (AU) server.

Solution

This Hotfix ensures that Apex Central can run the deploy command after downloading new components from the AU server.

Issue 4 (SEG-69509)

Inaccurate information may appear in Virus Event Notifications.

Solution

This Hotfix ensures that Virus Event Notifications display complete and accurate information.

Issue 5 (VRTS-4291)

Apex Central displays complete software version information in error pages.

Solution

This Hotfix prevents Apex Central from displaying the complete software version information in error pages.

Issue 6 (SEG-68531)

The wrong information displays in the "Action" field on Behavior Monitoring event notifications.

Solution

This Hotfix ensures that Behavior Monitoring event notifications displays complete and accurate information.

Trend Micro Apex One™ as a Service

This Hotfix resolves the following issue(s):

Issue 1 (SEG-69988)

The target policy count in the "Application Control Criteria" page becomes inaccurate after the Apex One Security Agent policy inherits policies.

Solution

This hotfix updates the Application Control files to resolve this issue.

Issue 2 (SEG-73228)

The Trend Micro Data Loss Prevention(TM) (DLP) service does not work normally in Google Chrome 80 and may cause it to stop unexpectedly.

Solution

This hotfix updates the DLP module to resolve this issue.

Issue 3 (SEG-68822)

Security Agents become offline after applying updates from an update agent.

Solution

This hotfix resolves this issue by ensuring that Security Agents use the correct session "INI_SERVER_SECTION" instead of "Global Setting".

Issue 4 (SEG-72100)

The Apex One Master Service may stop unexpectedly causing the server to become unavailable.

Solution

This hotfix updates the service to solve this issue.

Issue 5 (SEG-65277), (SEG-75522), (SEG-74826)

After installing the March 2020 upgrade on Apex One, users may encounter the following error message while deploying policies.

"Endpoint Sensor: No valid license"

Solution

This hotfix resolves the issue.

Issue 6 (SEG-73477)

Incomplete Live Investigation YARA scan results may appear in the "Summary" and "Details" pages, as a result, users will not be able to access and view YARA and the Root Cause Chain for certain protected computers.

Solution

This hotfix updates the Endpoint Sensor to resolve this issue.

Issue 7 (SEG-74927)

Sometimes, the Application Reputation List of the Application Control Criteria in the Apex Central web console displays "No result Found" after a Certified Safe Software Pattern update.

Solution

This hotfix updates the Application Control files to resolve this issue.

Issue 8 (SEG-73908)

When Apex One detects multiple viruses in a file, the detection names display merged and cannot be distinguished individually.

Solution

This hotfix resolves the issue by allowing Apex One to report only the last returned virus name.

Issue 9 (SEG-72750)

The Predictive Machine Learning (PML) folder exclusion settings are not applied to sub-folders.

Solution

This hotfix adds the sub-folders into the exclusion scope to ensure that the exclusion settings work normally.

Issue 10 (SEG-73800)

The length of the Scan Exclusion List (File Extensions) in the Apex One web console does not match the length of the list on the Apex Central web console.

Solution

This hotfix resolves helps ensure that the size of the list on both consoles are always consistent and remain under 30 bytes.

Issue 11 (SEG-68688)

When the Apex One server is added into the Microsoft(TM) Internet Explorer(TM) (IE) proxy exception list, the Apex One Security Agent still pings the proxy. As a result, the Apex One Security Agent becomes offline if the IE proxy points to a non-existent proxy server.

Solution

This hotfix ensures that the Apex One Security Agent handles the IE proxy exception list correctly to resolve the connectivity issue.

Issue 12 (SEG-76497)

When the DLP service is enabled on Apex One security agent computers, Google Chrome 80 and higher versions may stop unexpectedly while users upload file attachments in Webmail.

Solution

This hotfix updates the DLP module to resolve this issue and enable it to block the upload of file attachments in Webmail on Google Chrome.

Issue 13 (SEG-75065), (SEG-72197), (SEG-72870), (SEG-77611)

The Apex One Behavior Monitoring module may use up a large amount of CPU resources while handling hooked events in some heavy-loaded endpoints that experience a large number of events.

Solution

This hotfix updates the Behavior Monitoring module to optimize its performance on affected endpoints.

There are no issues for this Hotfix release.

Trend Micro Apex One™ (Mac) as a Service

There are no issues for this Hotfix release.

Enhancements

Trend Micro Apex Central™ as a Service

The following enhancements are included in this Hotfix:

Enhancement 1 (SEG-70034)

This Hotfix enables the "Device Type" field in device control logs to display "Mobile devices" instead of "Non-storage USB".

Enhancement 2 (SEG-52919)

This hotfix enables the Apex Central Threat Statistics widget to detect the following violation log types:

  • Firewall Violation
  • Behavior Monitoring
  • Network Content Inspection
  • Device Control
  • Suspicious Files
  • Predictive Machine Learning
Enhancement 3

Syslog Forwarding Enhancement

Apex Central allows you to forward Intrusion Prevention and Product Auditing Event logs to a syslog server.

Enhancement 4

Vulnerability Patches

Apex Central has patched Cross Site Scripting (XSS) and SQL injection vulnerabilities.

Enhancement 5

Password Complexity Enhancement

Apex One as a Service user account passwords and the Apex One Security Agent uninstallation password have the same password complexity requirements.

Enhancement 6

Security Agent Password Complexity

The Uninstall Security Agent feature includes enhanced password complexity requirements for better security.

Trend Micro Apex One™ as a Service

The following enhancements are included in this Hotfix:

Enhancement 1 (SEG-75139)

This hotfix enables the manual hash value list and file path list of the Application Control Criteria to support up to 100 entries.

Enhancement 2 (SEG-74759), (SEG-74482)

The Message DR feature may skip certain email file attachments during an email sweep in the Root Cause Analysis Chain. This hotfix applies the Endpoint Sensor May 2020 release which allows users to select more files for email sweeps.

Enhancement 3

This hotfix allows the Powershell command line to support up to 32767 characters to match the design of the ADE widget from Microsoft.

Enhancement 4

The Apex One server and Security Agents collect Windows event logs related to critical system events (move Security Agent, uninstall Security Agent, reset password) and sends the logs to Apex Central Product Auditing Event logs.

Enhancement 5

The Unload and Uninstall Security Agent feature includes enhanced password complexity requirements for better security.

Enhancement 6

Policy inheritance has been added to the Trusted Program List policy.

Enhancement 7

Security Agents can prevent ransomware attacks that leverage a vulnerability in the Encrypting File System (EFS) for Windows.

The following enhancements are included in this Hotfix:

Enhancement 1 (SEG-75254)

The Trend Micro Apex One server does not automatically uninstall the following antivirus software before installing the Apex One Security Agent.

  • Carbon Black Cloud Sensor 3.5.0.1627 x64
  • Carbon Black Cloud Sensor 3.5.0.1627 x86

Trend Micro Apex One™ (Mac) as a Service

There are no enhancements for this Hotfix release.

Additional Information

Trend Micro Apex Central™ as a Service

No additional information available.

Trend Micro Apex One™ as a Service

Security Agent version: 14.0.7867

Security Agent restart: Required

Estimated size of network traffic (in terms of bandwidth) required for deployment:

  • 32-bit Security Agent hotfix = 262 MB
  • 64-bit Security Agent hotfix = 328 MB
No additional information available.

Trend Micro Apex One™ (Mac) as a Service

Security Agent Version: 3.5.3409

Security Agent Restart Requirement: Not required

Estimated size of network traffic (in terms of bandwidth) required for deployment:

64-bit Security Agent Hotfix = 122.8 MB

2. Documentation Set

    The document set includes:

  • Trend Micro Apex One™ as a Service documents
    • Readme: Contains a list of known issues and may also contain late-breaking product information not found in the Online Help or printed documentation.
    • Knowledge Base: An online database of problem-solving and troubleshooting information. It provides the latest information about known product issues. To access the Knowledge Base, go to the following website: http://esupport.trendmicro.com
  • Trend Micro Apex Central™ as a Service documents
    • Administrator's Guide: A PDF document that provides detailed instructions for how to configure and manage the Trend Micro Apex Central™ as a Service console and features.
    • Data Protection Lists (Chapter 1 only): A PDF document that lists predefined data identifiers and templates for Data Loss Prevention.
    • Widget and Policy Management Guide: Explains how to configure Dashboard widgets and Policy Management widgets on the Trend Micro Apex Central™ as a Service console.
    • Automation API Guide: A PDF document that explains how to use Trend Micro Apex Central™ Automation APIs.
    • Online Help: Provides "how to's", usage advice, and field-specific information. The Help is also accessible from the Trend Micro Apex Central™ as a Service console.
  • Trend Micro Apex One™ server documents
    • Administrator's Guide: A PDF document that discusses getting started information and Trend Micro Apex One™ server administration.
    • Online Help: Provides "how to's", usage advice, and field-specific information. The Help is accessible from the Trend Micro Apex One™ server, agent, and Policy Server consoles, and from the OfficeScan Master Setup.
  • Trend Micro Apex One™ (Mac) server documents
    • Administrator's Guide: A PDF document that discusses getting started information and Trend Micro Apex One™ (Mac) server administration.
    • Online Help: Provides "how to's", usage advice, and field-specific information for Trend Micro. The Help is also accessible from the Trend Micro Apex One™ as a Service console.
  • Security Agent documents
    • Trend Micro Apex One™ Security Agent Online Help: Discusses getting started information, Trend Micro Apex One™ Security Agent installation procedures, and Trend Micro Apex One™ Security Agent management.
    • Trend Micro Apex One™ Security Agent Readme: Contains a list of known issues and may also contain late-breaking product information not found in the Online Help or printed documentation.
    • Trend Micro Apex One™ (Mac) Security Agent Online Help: Discusses getting started information, Trend Micro Apex One™ (Mac) Security Agent installation procedures, and Trend Micro Apex One™ (Mac) Security Agent management.

    Download the latest versions of the PDF documents and readme at our online documentation.

3. Post-installation Configuration

No post-installation steps are required.

4. Known Issues

Trend Micro Apex Central™ as a Service

Known issues in this release:

Known issue 1

The file name of the attached ZIP file for a generated report contains garbled text if the report name contains non-alphanumeric characters.

Known issue 2

The attached ZIP file for a generated report cannot be opened of the report name contains Traditional Chinese characters.

Known issue 3

If Apex Central as a Service is the Node Apex Central of an on-premises Hub Apex Central server, Apex Central as a Service might not be able to receive Suspicious Object Lists from the on-premises Hub Apex Central.

To resolve this issue, contact your support representative.

Trend Micro Apex One™ as a Service

Known issues in this release:

Known issue 1

Security Agent consoles running build 13.95 display an incorrect policy name. To resolve this issue, upgrade the Security Agent to 14.0. After the Security Agent contacts the server, the policy name displays correctly.

Known issue 2

Off-premises and Security Agents in Independent mode cannot update the Certified Safe Software Pattern from external update sources.

Known issue 3

Coexist mode Security Agents on endpoints with Windows Defender may experience installation issues or be unable to upload data to the Apex One server due to a file locking issue. To resolve this issue, add Endpoint Sensor (ESEServiceShell.exe and ESClient.exe) in the exclusions list of Windows Defender to prevent the locking issue.

Known issue 4

After copying a file to a remote server using a relative path as the source, Apex One is unable to translate the relative path into the full system directory.

Known issue 5

The quality of RCA analysis chain image files is reduced when viewing the files using Windows 10 Photo Viewer.

Known issue 6

When attempting to start a Historical Investigation from the Attack Discovery Detections widget that includes Registry value name or Registry value data criteria, the Historical Investigation displays an error message if the length of the Registry value name exceeds 260 characters or the Registry value data exceeds 64 characters.

Known issue 7

After updating the Attack Discovery Pattern file (tmesadp.ptn) on Security Agents, a database schema error may occur that causes the Endpoint Sensor feature to continuously report the same detections to the server during each synchronization. This causes duplicate records to display on the Apex Central server.

Known issue 8

Root Cause Analysis email attachment results may also include temporary files created when the user saved the file.

Known issue 9

The number of matched endpoints that display on a Root Cause Analysis chain may appear to be greater than the total if the Security Agent on an endpoint was uninstalled or no longer reports to the same managing server.

Trend Micro Apex One™ (Mac) as a Service

Known issues in this release:

Known issue 1

After enabling the Scan Time Machine option for Manual Scan and Scheduled Scan, Apex One (Mac) cannot perform any actions (clean, quarantine, or delete) on detected malware threats due to a permission limitation in Mac OS. Configured scan actions are displayed as unsuccessful in the product logs.

Known issue 2

When performing a historical investigation on Apex One (Mac) endpoints, the system replaces a backslash (/) with a colon (:) in file names, preventing users from searching for file names that contain backslashes in investigation results.

To resolve this issue, use a colon (:) to search for the files.

5. Contact Information

A license to Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, you must renew Maintenance on an annual basis at Trend Micro's then-current Maintenance fees.

Contact Trend Micro via fax, phone, and email, or visit our website to download evaluation copies of Trend Micro products.

https://www.trendmicro.com/en_us/contact.html

NOTE: This information is subject to change without notice.

6. About Trend Micro

Smart, simple, security that fits

As a global leader in IT security, Trend Micro develops innovative security solutions that make the world safe for businesses and consumers to exchange digital information.

Copyright 2020, Trend Micro Incorporated. All rights reserved.

Trend Micro, Trend Micro Apex Central, Trend Micro Apex One, Trend Micro Apex One (Mac) and the t-ball logo are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other marks are the trademarks or registered trademarks of their respective companies.

7. License Agreement

View information about your license agreement with Trend Micro at: https://www.trendmicro.com/en_us/about/legal.html

Third-party licensing agreements can be viewed:

  • By selecting the "About" option in the application user interface
  • By referring to the "Legal" page of the Administrator's Guide
Back to Top