Summary
This article is a summary compilation of current and previous WFBS 10.0 SP1 patches.
Please refer to the corresponding Readme file for details on patch enhancement/fix
Patch | Enhancement | Fixed Issue |
---|
Patch 2500 Readme |
- This Patch updates the Virus Scan API (VSAPI) engine to version 23.602.1001.
- This Patch updates the Self-Protection module in Worry-Free Business Security Agent to enhance product security.
- This Patch updates the Apache web server to version 2.4.58.
|
- This patch resolves the issue on Browser Exploit Prevention function which may cause slow content loading affecting user experience when visiting internal websites.
- This patch fixes the issue related to the Security Agent update process may prevent the process from completing successfully.
- This patch addresses an internal issue that may prevent the agent migration tool "Ipxfer.exe" and the server function "Move Security Agent" from working properly.
- This patch resolves the issue where the system does not display the same Virus Scan Engine version on the Security Server and Security Agent consoles.
- This patch fixes the issue where the system includes multiple "Unable to Update" warning messages in an application event log.
- This patch resolves the issue where users cannot start an Aggressive Scan on Security Agents from the Security Server console.
- This patch resolves the issue where the Security Server may not save the firewall configuration.
- This patch fixes the issue where Security Agents may not send detection reports to the Security Server.
- This patch resolves the issue where the system may generate empty folders in the "C:\Windows\Temp\" directory.
|
Patch 2497 Readme |
- This patch enables Worry-Free Business Security to support endpoints running Microsoft Windows 11 23H2 Update.
- This patch updates the Virus Scan API (VSAPI) engine to version 23.580.1004.
- This patch updates the Self-Protection module in WFBS Agent to enhance product security.
|
- This patch resolves the issue where after restarting the Microsoft Exchange Server, the system automatically resends outdated virus detection warning notifications.
|
Patch | Enhancement | Fixed Issue |
---|
Patch 2495 Readme |
- This Patch updates the Virus Scan API (VSAPI) engine to version 22.610.1017.
- This Patch removes the "Scan mapped drives and shared folders on the network" option for Real-time Scan. For more information, refer to this KB article.
|
- After Security Agent is unloaded, the system may not be able to terminate related services.
- The system is unable to perform a Manual Update through Security Agent console successfully.
|
Patch 2472 Readme |
- This Patch updates the Apache web server to version 2.4.56.
- This Patch updates the Advanced Threat Scan Engine (ATSE) to version 9.1.1008.
|
- The system may send outdated notifications when Security Server service restart or system reboot.
- The system may display garbled text for virus detection logs on the web console.
|
Patch 2459 Readme |
- This Patch enables Worry-Free Business Security to support Azure Code Signing (ACS) for user-mode binary file signing.
|
- The Security Agent icon may not appear in the system tray after reinstallation.
- The system may not display the correct version number for the Smart Scan Pattern on the Security Server console.
- The system may display garbled text for virus logs on the Security Server console.
- The Security Agent process "TmCCSF.exe" may be unresponsive.
- When the "Thunderbird" application is started on an endpoint, the Security Agent displays the "Protection at Risk" status.
|
Patch | Enhancement | Fixed Issue |
---|
Patch 2454 Readme |
- This Patch enables Worry-Free Business Security to support endpoints running Microsoft Windows 10 and Windows 11 2022 Update.
|
- The Smart Scan service may stop unexpectedly and the Security Agent is unable to connect to the local Smart Scan Server.
- The Security Agent tool "IPXfer.exe" does not function properly.
|
Patch 2436 Readme |
- This Patch updates the Apache web server to version 2.4.54.
|
- Users might experience performance issues with the Trend Micro Security Server Database Service.
- After applying Patch 2419, users might not be able to open the Security Server console and the Sec
|
Patch 2419 Readme |
- This patch updates the self-signed server certificate for the Security Server console.
- This patch includes the enhancement for the Advanced Threat Scan Engine.
|
- The Real-Time Scan process may become unresponsive on Security Agent endpoints.
- After applying Patch 2403, the system may generate Windows event logs for false-positive alerts on Security Agent endpoints running on Windows 8.1.
- After applying Patch 2403, the Smart Scan Service may not function properly.
- Customers who apply the recently released Microsoft Windows 11 (KB5014019 and/or KB5014697) patches and reboot would then find that the Trend Micro UMH driver would stop.
|
Patch 2403 Readme | |
- Website access may be slow for some users.
- Users may not be able to execute Powershell commands.
- In some situations, the system may not be able to detect potentially malicious files downloaded from websites.
|
Patch 2390 Readme |
- This Patch updates the Apache web server to version 2.4.52.
- This Patch applies security enhancements to the Worry-Free Business Security local Smart Scan Server.
|
- The Worry-Free Business Security Server console might become inaccessible.
- The Worry-Free Business Security Agent process might crash unexpectedly.
- A CGI error occurs when using "ClnDiag" administrator tool to check the connection status.
- An "Unknown OS" message appears on the device list of Worry-Free Business Security Server console when the operating system is Microsoft(TM) Server 2022.
|
Critical Patch 2380 Readme |
- This Critical Patch updates the module related to the Smart Protection Server to resolve an Out-Of-Bounds Read security issue.
| |
Patch | Enhancement | Fixed Issue |
---|
Critical Patch 2380 Readme |
- This Critical Patch updates the module related to the Smart Protection Server to resolve an Out-Of-Bounds Read security issue.
| |
Patch 2368 Readme |
- Platform Support - This Patch enables Worry-Free Business Security Agent to support Microsoft(TM) Windows(TM) 11 and Server 2022.
- Windows Update - This Patch enables Worry-Free Business Security Agent to support the Microsoft Windows 10 November 2021 Update.
- Smart Scan Server - This Patch applies performance and security enhancements to the Worry-Free Business Security local Smart Scan Server.
|
- The Microsoft Internet Explorer(TM) web browsers encounters a performance issue when the Browser Exploit Prevention feature is enabled.
- Worry-Free Business Security Agent computers may restart unexpectedly or experience blue screen of death (BSOD).
|
Patch 2342 Readme | |
- After triggering Manual Scan through the Security Agent, the scan does not complete and the progress bar remains at zero percent.
- A performance issue occurs on protected computers when a non-existent UNC path has been added in the Trusted Program list.
- The following message that displays on the server platform may mislead users:
"Resource Shortage“ Remaining disk space on the Security Server is less than the specified percentage." - The terminal server may stop unexpectedly which can trigger a performance issue on the server computer.
- An issue may cause Adobe Acrobat DC Subscriptions to fail.
|
Patch 2329 Readme |
- Windows Update - This Patch enables Worry-Free Business Security to support the Microsoft(TM) Windows(TM) 10 May 2021 Update.
- Web Browser Support - This Patch enables Worry-Free Business Security to check URLs and websites in version 90.0 of the Google(TM) Chrome(TM) web browser.
- Security Agent Console - This Patch enables the Worry-Free Business Security Agent to automatically align the date format on the Security Agent console with the date configuration of each computer.
|
- Tool Vulnerability Scanner (TMVS) might stop unexpectedly on the Windows 10 platform.
- The Threat Encyclopedia link redirects to the wrong website.
- The "Restart browser" warning message pops up repeatedly on Security Agents after an update.
- The "xpupg.exe" process may stop unexpectedly while the Security Agent restarts or applies updates.
- The Web Reputation rating server is configured in English.
- The "Virus Pattern" information does not display on the Security Server console in Conventional Scan mode.
- An issue may prevent Security Agents from retrieving the latest virus definitions.
- When users view the device list and sort the items on the list, the sorting order reverts to default on the next page.
- A performance issue occurs on protected computers because the event throttling setting is missing.
|
Patch 2309 Readme |
- Apache(TM) - This patch updates the Apache module to prevent potential vulnerabilities.
- Microsoft(TM) Edge(TM) Chromium version 88/89 - This patch enables Worry-Free Business Security to check URLs and websites in the new Chromium-based Edge web browser.
|
- On the Worry-Free Business Security agent console, the browsing window does not appear after users click the "Browse" button.
- The Worry-Free Security Agent appears twice on the startup menu of the task manager.
- In Update Deployment logs on the Security Server, the "Date/Time" field displays "N/A" while "Information Unavailable" appears on the "Result" field.
- Outdated pattern files remain on the Security Server.
- An issue prevents the Messaging Security Agent from saving configuration changes.
|
Patch 2274 Readme |
- Allow Trend Micro Remote Manager(TMRM) Agent to support Transport Layer Security(TLS) 2.0
|
- The copyright year on the Worry-Free Business Security web console is 2020.
- Some Adobe Acrobat DC Subscriptions issues have been detected.
- A Citrix Gateway VPN issue has been detected.
- An issue prevents the Worry-Free Business Security server from applying updates manually from the "Intranet location containing a copy of the current file" update source.
- Ping and Nslookup commands encounter crash when Forefront Threat Management Gateway(TMG) client is installed.
|
Patch | Enhancement | Fixed Issue |
---|
Patch 2260 Readme |
- Windows Update - This patch enables Worry-Free Business Security to support Microsoft(TM) Windows(TM) 10 October 2020 Update.
|
- An issue causes Apache updates to fail.
- Blue screen of death (BSOD) occurs on multiple agent computers.
- Some unsupported operating systems appear on the list of supported operating systems on the web install page.
- Agent services stop unexpectedly during startup.
- Trend Micro Security Agent Listener stops unexpectedly.
- Meerkat still blocks an exe file even when the "Prompt users before executing newly encountered programs downloaded through HTTP or email applications" option is disabled.
|
Patch 2245 Readme | |
- Patch installation fails while replacing the "isapiclient.dll" library.
- After Patch 2228 is applied, Worry-Free Business Security does not receive any data feedback from the BIF server.
- The old CCSF pattern file "smvptn" is not purged automatically
- The copyright date has not been updated.
- An issue prevents successful patten updates.
- The PccNT service stops responding after starting a manual scan (SR: 03591782).
- After Patch 2228 is applied, the agent update process goes into an infinite loop.
- After Patch 2203 is applied, the agent update process goes into an infinite loop.
- Remove UMH-related functions from server platforms.
|
Patch 2228 Readme |
- Windows Update - This patch enables Worry-Free Business Security to support Microsoft(TM) Windows(TM) 10 May 2020 Update.
- Edge Support - This patch enables Worry-Free Business Security to support the new Microsoft Edge(TM) web browser that is based on Chromium.
|
- An issue prevents Worry-Free Business Security agents from upgrading to Patch 2190.
- An issue prevents users from uninstalling the Worry-Free Business Security Windows Security Center Service using the SA_Unintall tool.
- Worry-Free Business Security generates blank PDF reports.
- Blue screen of death (BSOD) occurs on some protected computers.
- Some agents remain under "Updating Program" status for a long time.
- Users cannot access certain websites when the Trend Micro Osprey Plugin is enabled.
- Worry-Free Business Security does not create an event log when users change the console password.
- Issues prevent users from configuring the exclusion settings on clients successfully.
- A high CPU usage issue occurs after users install Patch 2203.
|
Patch 2203 Readme | |
- The OpenSSL version Worry-Free Business Security 10.0 Service Pack 1 requires an upgrade.
- The "Sharing Services" category on the blocking page does not match the corresponding category on the URL Filtering policy.
- A compatibility issue may prevent Mimecast from working normally on agent computers.
- A protected computer may restart repeatedly after the second or third scheduled scan.
- Some agents appear offline and remain in updating status because "w3wp.exe" stops unexpectedly.
- Some protected computers may stop responding.
|
Patch 2190 Readme | |
- Worry-Free Business Security is affected by a Local Privilege Escalation vulnerability and an IPC Authentication Bypass vulnerability.
- There is a typographical error on the agent installation screen.
- An issue prevents users from enabling the "Antispam – Spam detections in total messages received exceed" notification.
- An Apache(TM) Service error appears in the system eventlog.
- An "AgentStatusDC.exe" error appears on the event viewer.
- The Trend Micro Security Agent listener service may not shutdown properly after receiving a pre-shutdown command.
- Certain vulnerabilities in Worry-Free Business Security may allow dll side loading at libcurl/openssl.
- The combination of two possible 0-day directory traversal vulnerabilities leads to a Remote Code Execution (RCE) vulnerability which can grant attackers SYSTEM privileges to the management server.
- The Worry-Free Business Security is affected by a Directory Traversal Authentication Bypass Vulnerability.
|
Patch | Enhancement | Fixed Issue |
---|
Patch 2185 Readme |
- Windows Update - This patch enables Worry-Free Business Security to support Microsoft(TM) Windows(TM) 10 November 2019 Update.
|
- An issue triggers TmListen to stop unexpectedly repeatedly.
- The Worry-Free Business Security Agent uses up a large amount of memory.
- Security Agents may restart repeatedly after the second or third scheduled scan.
- An issue prevents Worry-Free Business Security from cleaning spyware completely.
- The Security Server cannot successfully update the pattern because the Master Service stops and freezes the manual pattern update at 80% complete.
- "cgiRecvFile.exe" is affected by a path traversal vulnerability.
- The TMAS module encounters an error after users install a patch or a Security Server upgrade.
- Agent installation package exceeds 2GB after patch 2179 is applied and the installation might be failed.
|
Patch 2179 Readme |
- ActiveUpdate (AU) Security - This patch enables the Worry-Free Business Security server to update AU patterns and files using a more secure HTTPS protocol.
|
- There are multiple Vulnerabilities in Apache 2.4.29.
- "Ofcservice.exe" stops responding while processing log queries on the Worry-Free Business Security server web console.
- ATTK Scan detection logs cannot be uploaded because these contain the wrong "FunctionType".
- Users cannot login to the Worry-Free Business Security web console even after resetting the password using the reset password tool.
- "Setup.exe" stops unexpectedly while upgrading Worry-Free Business Security to version 10.0 Service Pack 1 on the Microsoft(TM) Windows(TM) Server 2008 Service Pack 2 platform.
- There are OpenSSL vulnerabilities in Worry-Free Business Security 10.0 Service Pack 1.
- A vulnerability may allow attackers to bypass root authentication and logon to the Worry-Free Business Security web console.
- An attacker may be able to execute codes through a .dll file.
- Users cannot install the Security Agent because a higher version of Microsoft Visual C++ 2017 already exists.
- Agents using the 64-bit IIS appear offline after users apply version 10.0 Service Pack 1 Patch 2178.
- After users apply Patch 2178, some Spyware or Adware are detected from non-existing registry keys during manual/scheduled scans.
- The setup process terminates unexpectedly because the patch installer cannot stop the update process.
|
Patch 1569 Readme | |
- A vulnerability may allow attackers to bypass root authentication and logon to the Worry-Free Business Security web console.
- Users may not be able to login to the Worry-Free Business Security console even after resetting the password tool using the password reset tool.
- Users continuously receive email notifications that state that virus detections have exceeded the threshold.
|
Patch 1559 Readme | |
- The URL filtering feature may not be able to block certain URLs.
- An error occurs when users save changes to the Scheduled Scan settings.
- Microsoft(TM) Windows(TM) Server 2019 appears as "Windows Server 2016" on the Worry-Free Business Security web console.
- There is a typographical error on the "LiveStatus" page of the Worry-Free Business Security web console.
- An error occurs during Remote Installation.
- The Device Control feature may not work under certain conditions.
|
Patch 1531 Readme | |
- Microsoft Office and Google Chrome may stop unexpectedly on some protected computers.
- Users do not receive violation notifications.
- The Security Server Master Service stops unexpectedly while saving information in the database if the information is in the wrong format.
- The Security Agent receives invalid authentication requests from the Security Server.
|
Patch 1516 Readme | |
- Several "Database Backup Failed" events appear in console event logs.
|
Trend Micro recommends to install this Patch only on computers protected by Worry-Free Business Security 10.0 with Service Pack 1.