<<USE COURIER REGULAR 10 FONT IF YOU WOULD LIKE TO PRINT THIS DOCUMENT>> Trend Micro Incorporated August 12, 2020 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Trend Micro(TM) Portal Protect 2.6 - GM for English - Windows - 64 Bits Critical Patch - Build 1043 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Contents ========================================================== 1. Overview of This Critical Patch Release 1.1 Issues 1.2 Files Included in This Release 2. Documentation Set 3. System Requirements 4. Installation 4.1 Installing 4.2 Uninstalling 5. Post-installation Configuration 6. Known Issues 7. Release History 8. Contact Information 9. About Trend Micro 10. License Agreement ========================================================== 1. Overview of This Critical Patch Release ======================================================================== 1.1 Issues ====================================================================== This critical patch resolves the following issues: Issue 1: A directory traversal vulnerability occurs when PortalProtect downloads engine files or pattern files from the local ActiveUpdate (AU) server. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution 1: This critical patch updates the Trend Micro ActiveUpdate modules to resolve this issue. 1.2 Files Included in This Release ===================================================================== A. Files for Current Issue --------------------------------------------------- Filename Build No. -------------------------------------------------------------------- [PortalProtect] Build64.exe 2.86.0.1113 cert5.db n/a ciuas64.dll 1.0.0.2075 ciussi64.dll 2.0.0.2074 expapply64.dll 8.4.2.0 expbuild64.dll 8.4.2.0 icrcauapi.dll 2.5.0.1115 liblwtpciu64.dll 1.0.0.1005 patch64.exe 2.86.0.1113 patchw64.dll 12.22.0.0 pbld64.dll 12.20.0.0 psmc64.dll 8.4.2.0 TmUpdate64.dll 2.86.0.1113 x500.db n/a B. File for Previous Issues --------------------------------------------------- Not applicable. 2. Documentation Set ======================================================================== To download or view electronic versions of the documentation set for this product, go to http://docs.trendmicro.com In addition to this Readme file, the documentation set for this product includes the following: - Online Help: The Online Help contains an overview of features and key concepts, and information on configuring and maintaining product. To access the Online Help, go to http://docs.trendmicro.com - Installation Guide (IG): The Installation Guide contains information on requirements and procedures for installing and deploying product. - Administrator's Guide (AG): The Administrator's Guide contains an overview of features and key concepts, and information on configuring and maintaining product. - Getting Started Guide (GSG): The Getting Started Guide contains product overview, installation planning, installation and configuration instructions, and basic information intended to get product 'up and running'. - Support Portal: The Support Portal contains information on troubleshooting and resolving known issues. To access the Support Portal, go to https://success.trendmicro.com 3. System Requirements ======================================================================== 1. Trend Micro Portal Protect 2.6 GM Build 1037 - English - Windows - x64 4. Installation ======================================================================== This section explains key steps for installing the critical patch. 4.1 Installing ===================================================================== To install this critical patch on Normal Servers (x64): 1. Copy the self-extracting file "pp_26_win_en_criticalpatch1_b1043.exe", to any location on the PortalProtect server. 2. Run the "pp_26_win_en_criticalpatch1_b1043.exe" file. 3. In the setup screen, click "Install" and follow the on-screen instructions to complete the installation.The "Installation successful!" message appears after the system completes the installation. NOTE: This critical patch restarts the following services during installation: * Microsoft SharePoint Timer Service * Microsoft World Wide Web Publishing Service * Trend Micro PortalProtect_Master service * Trend Micro PortalProtect_SystemWatcher service 4.2 Uninstalling ===================================================================== To roll back to the previous build: 1. Open the registry editor. Click "Start > Run". Type "REGEDIT" and press "Enter". 2. Take note of the "Backup Dir" value in the "\HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro \PortalProtect\Hotfix\PP2.6 Critical Patch 1\"registry key. A typical value would be "C:\Program Files\Trend Micro\ PortalProtect\HotFix\B-1043". 3. Run "Uninstall.bat" in the backup folder to start the rollback. If the rollback is successful, the message "Remove installation successful" appears. 4. Click "OK." 5. Post-Installation Configuration ======================================================================== No post-installation steps are required. NOTE: Trend Micro recommends that you update your scan engine and virus pattern files immediately after installing the product. 6. Known Issues ======================================================================== There are no known issues for this critical patch release. 7. Release History ======================================================================== For more information about updates to this product, go to: http://www.trendmicro.com/download 8. Contact Information ======================================================================== A license to Trend Micro software usually includes the right to product updates, pattern file updates, and basic technical support for one (1) year from the date of purchase only. After the first year, you must renew Maintenance on an annual basis at Trend Micro's then-current Maintenance fees. Contact Trend Micro via fax, phone, and email, or visit our website to download evaluation copies of Trend Micro products. https://www.trendmicro.com/en_us/contact.html NOTE: This information is subject to change without notice. 9. About Trend Micro ======================================================================== Smart, simple, security that fits As a global leader in IT security, Trend Micro develops innovative security solutions that make the world safe for businesses and consumers to exchange digital information. Copyright 2020, Trend Micro Incorporated. All rights reserved. Trend Micro, Portal Protect, and the t-ball logo are trademarks of Trend Micro Incorporated and are registered in some jurisdictions. All other marks are the trademarks or registered trademarks of their respective companies. 10. License Agreement ======================================================================== View information about your license agreement with Trend Micro at: https://www.trendmicro.com/en_us/about/legal.html Third-party licensing agreements can be viewed: - By selecting the "About" option in the application user interface - By referring to the "Legal" page of the Administrator's Guide