Seit dem 18.06.2019 hat der Hersteller Trend Micro für sein Produkt Officescan XG ein neues Update herausgebracht. Das Server-Build 5247 und die zugehörige Agenten-Version 5454 behebt die folgenden Probleme:
- A directory traversal vulnerability may allow an attacker to log on to the OfficeScan Management Console as a root user
- A directory traversal vulnerability may allow an attacker to extract files from an arbitrary zip file to the specific folder in OfficeScan server
- An issue prevents OfficeScan agents running on the Microsoft(TM) Windows(TM) 10 platform from reporting their correct status to the OfficeScan server. As a result, these agents appear as „Endpoints with Non-compliant Services“ on the OfficeScan web console.
- An error occurs while the Certificate Authentication Manager Tool re-establishes communication between the OfficeScan server and managed OfficeScan agents.
Zusätzlich werden die folgenden Anpassungen zur Verfügung gestellt:
- The OfficeScan Master Service stops unexpectedly while restarting if the length of the OfficeScan agent’s full domain name exceeds the maximum length.
- Online OfficeScan agents may appear as „Offline“ on the OfficeScan web console. Users need to restart the agents for the correct connection status to appear.
- After changing an agent’s connection setting on the web console, the agent is not moved to the target server because the server SSL port information is incorrect.
- The OfficeScan agent does not change to offline status when the computer shuts down. This happens because the SSL function cannot be initialized while the computer is shutting down.
- The OfficeScan agent does not send the „Logon User“ information to the OfficeScan server when the OfficeScan server restricts the user’s access to the OfficeScan agent console from the system tray or from the Microsoft(TM) Windows(TM) „Start“ menu.
- An issue related to the OfficeScan NT Listener service („TmListen.exe“) may cause the OfficeScan agent GUID to change unexpectedly.
- When upgrading an OfficeScan client computer to Microsoft(TM) Windows(TM) 10 April 2018 Update (Redstone 4), the Trend Micro Early Boot Clean driver may add unnecessary blank lines to the „ServiceGroupOrder“ registry value. This can cause blue screen of death (BSOD) after the agent computer restarts.
- OfficeScan agents running on Microsoft(TM) Windows (TM) 10 cannot upgrade to build 1903.
- An issue prevents users from uninstalling OfficeScan agents with the correct agent uninstallation password through Windows Installer (msiexec.exe) after applying OfficeScan XG Service Pack 1 Critical Patch 5383.
Über die Download-Seite kann der „Critical Patch“ in Englisch sowie Deutsch heruntergeladen werden.