Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Release details of Trellix ESM 11.6.3
For release dates and version number, see KB90422.
Rating
The rating defines the urgency for installing this update.
This release is a high-priority for all environments. Failure to apply high priority updates might result in potential business impact.
Upgrade Considerations
Trellix ESM 11.6.x and higher does not support environments with Distributed TESM configurations.
When upgrading to 11.6.x for the first time the normal process to upgrade HA receivers through the UI needs to be slightly altered.
- Refer to Upgrade HA receivers in Trellix Enterprise Security Manager 11.6.x Installation Guide.
- Skip step 6.
- On step 7a, select the primary receiver instead of the secondary receiver in Receiver Management.
New features and changes
This release includes these changes.
- Updated the OpenSSL library to v1.0.2.zg.
- Updated the NPP and Syslog collectors to support cipher suites using ECDHE for key exchange. For more information see KB96375.
Resolved issues
This release provides resolution for the following issues.
| Category | Reference | Resolution |
|---|---|---|
| Upgrade | SIEM-38822 | Resolved an issue that caused the 11.6.2 upgrade to fail on an ESM or ELM with an attached DAS device. |
| Collectors | SIEM-38637 | The NPP collector now supports cipher suites using ECDHE for key exchange - ECDHE-RSA-AES256-GCM-SHA384, ECDHE-RSA-AES256-SHA384, ECDHE-RSA-AES128-GCM-SHA256 and ECDHE-RSA-AES128-SHA256. |
| Collectors | SIEM-35355 | The Syslog collector now supports cipher suites using ECDHE for key exchange - ECDHE-RSA-AES256-GCM-SHA384, ECDHE-RSA-AES256-SHA384, ECDHE-RSA-AES128-GCM-SHA256 and ECDHE-RSA-AES128-SHA256. |
| Security | SIEM-38642 | Updated the OpenSSL library to v1.0.2.zg to resolve CVE-2023-0286, CVE-2022-4304, and CVE-2023-0215. |
This release provides resolution for the following content issues through a rule update since Trellix ESM 11.6.2.
| Category | Reference | Resolution |
|---|---|---|
| 3rd Party ASP | SIEM-38572 | Updated the parsing rule 1070108 and added parsing rule 1070817 for the Check Point via Syslog data source to better handle audit messages from Check Point. |
| 3rd party ASP | SIEM-38438 | Updated the parsing rule 1011177 for the InterSect Alliance Snare for Windows data source. |
| 3rd Party, Windows Rules | SIEM-38018 | Added parsing rule 43-432005150 for the Microsoft Windows Event Log - WMI data source. |
| 3rd Party, Windows Rules | SIEM-38017 | Updated the parsing rule 43-432005120 for the Microsoft Windows Event Log - WMI data source. |
| 3rd Party | SIEM-37745 | Added parsing rules 43-432005120, 43-432005150, 43-475012160, 43-475013170, 43-475015350, 43-475020410, 43-475028890, 43-476012160, 43-476013170, 43-476015350, 43-476020410, and 43-476028890 for the Microsoft Windows Event Log - WMI data source. |
| 3rd Party, Windows Rules | SIEM-37441 | Updated the parsing for MSSQL events via WMI. |
| 3rd Party | SIEM-37098 | Added parsing rule 1070816 to the Trellix IPS Manager data source. |
Known issues
For a list of known issues in this product release, see KB90422.