Endpoint Protector Client Bug Fix List

:pushpin: Looking for a bug fix list for all versions of Endpoint Protector Client?
All bug fixes will automatically be added here!

2602.0 Updates

Netwrix Endpoint Protector Client version 2602 Released (Now with Hotfix 1)

February 5, 2026

The following table contains a comprehensive list of updates and fixes introduced in this version:

Component Description Case # Escalation #
Security Endpoint Protector Components Refreshed Upgraded components for Libmagic, OpenSSL 398993, 400329, 405642
Security **Executable renaming to reduce false positives **BrowserBroker.exe has been renamed to EppExtensionHost.exe to eliminate false positive virus detections (CVE: Win32:CVE-2019-0566-A) in the EPP client archive. The new name has been verified and no longer triggers alerts on VirusTotal. Note: Please update your antivirus exclusions to reflect the new executable names. 408618 00463758, 00461324
General Enhanced tamper protection against forced uninstallation Strengthened tamper protection to prevent EPP Client uninstallation using third-party tools such as Revo Uninstaller and IOBit Uninstaller, even when uninstall password and tamper mode are enabled. Additional improvements were made to better handle uninstallation attempts when offline. 320104
General Improved IPv6 communication between EPP Client and Server Fixed an issue where the EPP Client installer did not accept IPv6 IP addresses and required DNS AAAA records instead. The EPP Client now supports binding to both IPv6 IP addresses and DNS records across all platforms. 408636
DC **Enhanced mobile device control on macOS **Mobile device blocking for iPhone and Android devices on macOS is now more reliable, ensuring devices are consistently restricted from mounting in Finder and other applications. This update simplifies configuration, improves consistency, and provides effective control without impacting device charging. 407826 00460417
DC **Improved compatibility with Axpert application when File Tracing is enabled **Resolved an issue where enabling File Tracing caused the Axpert application to fail to open. Axpert now runs correctly with File Tracing enabled. 408967 00456905
DC Audio device permission handling improvement on Windows Resolved an issue where manually disabled audio devices were automatically re-enabled by the agent when permission was set to Allow. Disabled devices now remain disabled as expected, and inactive states are no longer intercepted. 409970 00460253
DC mproved detection and monitoring of HID devices in EPP Resolved an issue where devices with specific HID identifiers (e.g., HID_DEVICE_UPR:xxxxxx, PID: xxxxx, VID: xxxx) were recognized in Device Manager but not detected by Endpoint Protector, even when USB device access was restricted. These HID devices are now properly detected and monitored by EPP. 413877 00433152
CAP **Improved OneDrive differentiation without DPI **EPP client can now distinguish between OneDrive Business and OneDrive Personal on macOS and Windows without relying on DPI. This update enables more precise monitoring, allows DPI to be disabled for OneDrive 409112, 369333 00429530
CAP OCR text handling in EPP client logs Previously, OCR-extracted text from image files was logged in the EPP client log during debug mode, even when obfuscation was enabled. Logging of OCR text during hashing scans has now been suppressed to prevent potential exposure of confidential information. 409223
CAP OCR clipboard blocking reliability on macOS Corrected an issue where images containing sensitive content were not blocked when pasted into Teams, Slack, or email in monitored browsers on macOS, despite CAP clipboard restrictions and OCR being enabled. Images are now properly blocked and reported according to policy settings. 320056, EPP-8651 00421283
CAP Web Dropbox file upload blocking behavior improvement Resolved an issue with web Dropbox where files containing confidential information, when blocked by CAP policy with DPI enabled, would remain in a syncing state and could not be canceled, ultimately being uploaded after about 90 seconds. The blocking process now properly prevents upload and allows users to cancel the transfer without needing to close the browser tab. 320096, 409083
CAP Improved CAP policy enforcement for special characters Resolved an issue where CAP policies failed to block strings containing special characters, such as Korean driving licenses, when using clipboard restrictions. These patterns are now correctly detected and blocked according to policy settings. 345111 341233
CAP Clipboard monitoring performance improvement for Excel on Windows Resolved delays and interface freezes when performing copy/paste operations on large Excel files with clipboard monitoring enabled, ensuring smoother user experience. 345857, 403888 00455431, 00435855, 340648, 00445881
CAP Improved compatibility with OneDrive on macOS under CAP policies Resolved an issue where OneDrive for macOS could fail to start if EPP client blocked access to certain configuration or database files due to CAP policy settings. OneDrive now starts reliably when CAP policies are applied. 346410
CAP Improved file shadow upload performance for Mac Mail and Printers Addressed delays where file shadows from Mac Mail app or printing actions took excessive time to upload to the server with DPI and file shadowing enabled. File shadows now upload promptly as expected. 346488
CAP Correct CAP policy enforcement for browsers with URL categories enabled and DPI disabled Resolved an issue where CAP policies did not block files in browsers when URL categories were enabled but DPI was disabled. Files are now correctly blocked as expected in this configuration. 357464
CAP Obfuscation of email subject in logs and UI Resolved an issue where email subjects containing confidential data were written in plain text in EPP client logs and displayed in the server UI, even with obfuscation enabled. Subjects are now properly obfuscated in both logs and UI across supported platforms. 363919
CAP Content Aware Report accuracy with Print Screen blocking policies Resolved an issue where print screen events blocked by CAP “Block Only” policies were still displayed in the Content Aware Report table. Events are now correctly excluded from reports as expected. 399803, 409874
CAP Correct application identification for cloud file uploads with DPI disabled Resolved an issue where uploads to Microsoft Teams were incorrectly detected as Outlook (Attachments) in Content Aware Reports when DPI was disabled. Reports now display the correct application as expected. 399904
CAP Improved CAP enforcement for blocking source code printing Resolved an issue where source code could still be printed from Notepad despite CAP policies configured to block such actions via printers. Printing of source code is now correctly blocked according to policy. 403776 00429095
CAP Improved OCR detection of threats in images attached via Outlook on Windows10 Resolved an issue where threats in images sent as Outlook attachments were not detected or reported when OCR was enabled. Image threats are now properly identified and reported. 403928 00451505
CAP Improved file remediation handling for AI chat uploads Resolved an issue where files sent via AI chat platforms such as Copilot and ChatGPT required multiple rounds of remediation due to being detected as different file types. Remediation now works as expected and files can be successfully sent after the first action. 405948
CAP Shadow icon accuracy in remediation logs without file tracing Resolved an issue on Mac and Linux where the shadow icon was missing from “Content Remediation Session Active” logs when CAP shadowing was enabled but file tracing was turned off. The shadow icon now appears correctly when files are found on disk during remediation. 408907
CAP **Improved CAP enforcement for Slack installed from Microsoft Store or msix package **Resolved an issue where file uploads in Slack installed via Microsoft Store or msix package were not monitored or blocked by CAP policies when DPI was disabled. Uploads are now correctly blocked and reported according to policy settings. 408926
CAP Resolved infinite print loop with Palo Alto Cortex and EPP Agent on macOS Fixed an issue where printing files flagged by a Report Only CAP policy resulted in an infinite print job loop when both Palo Alto Cortex and EPP Agent were installed on macOS. Printing now completes as expected without repeated restarts. 408964
CAP OCR scanning for image attachments in Outlook on macOS Resolved an issue where image files attached in Outlook were not OCR scanned and therefore not blocked according to policy. Image attachments are now properly scanned and blocked when containing threats. 409464
CAP Correct case-sensitive detection in custom denylist dictionaries Resolved an issue where case-sensitive custom dictionaries did not properly detect threats when words appeared in different capitalization formats. Files are now scanned and threats are reported accurately according to case sensitivity settings. 409559 00462396
CAP Accurate application detection for paste restrictions in EPP Notifier Resolved an issue where paste restrictions incorrectly reported Outlook instead of Teams when the Teams application process was detected as msedgewebview2.exe. Paste actions are now accurately attributed to the correct application in logs. 409573 00462638
CAP **Improved detection of image files in ZIP archives for CAP policies **Resolved an issue where image files within ZIP archives uploaded through web browsers were not detected or blocked when DPI and OCR were enabled, allowing policy bypass. CAP policies now properly inspect and enforce restrictions on images inside compressed archives. 410071
CAP Notification template handling for long or multi-byte policy names Resolved an issue where notification templates failed to display correctly if the CAP policy name exceeded the byte limit or contained multi-byte special characters. Notification templates now display as expected for policies with longer or special character names. 410695 00463434
CAP Excess WebUpload Logs Generated for Specific Websites Resolved an issue where EPP generated excessive WebUpload logs when users accessed certain websites (e.g., geeksforgeeks.org, trendyol.com, shop.mango.com). This occurred because background site requests with text content were being reported as text file uploads. The new build includes additional conditions to automatically ignore scanning such requests on these websites, addressing the customer’s concern. 366638 00419396
CAP Fixed: DC Transfer Limit Not Triggering on Linux Resolved an issue where enabling the DC transfer limit did not prevent additional file transfers once the limit was reached on Linux systems. CAP transfer limit continues to work as expected. 418925
CAP Fixed: Incorrect CAP Policy Report Creation for Print Screen Actions Resolved an issue where the “Report Only” CAP policy action failed to generate reports in the “Content Aware Reports” section, while the “Block Only” action was incorrectly creating reports. CAP policy report generation now works as intended: “Report Only” creates a report and “Block Only” does not. 418757
DPI Improved QUIC protocol management for Firefox on macOS QUIC protocol management for Firefox now works for installations in both the default location and user-specific Applications folders under /Users on macOS, covering more common usage scenarios. 410476
DPI Improved website compatibility with Stealthy DPI Connection handling in the Stealthy Deep Packet Inspection (DPI) connector has been improved to support successful loading of websites like https://sma.bobcard.co.in, resolving issues with connection failures caused by improper disconnect timing. 411528
DPI File hash and shadowing reporting for recently modified files Resolved an issue where file hashes and shadowing were not performed for files that had just been modified, due to timing between hash calculation and request scanning. Enhancements to scanning order now ensure that files correctly appear in Content Aware Reports with their hash and download shadows. Further improvements are planned to minimize such cases and optimize reliability. 319819
DPI Network connection stability improvements in DPI on macOS Addressed rare issues on macOS where network connections could be dropped or routed incorrectly when DPI was enabled, particularly under high system load or with many concurrent connections. Enhancements to connection list management and timing now ensure reliable downloads and accurate server routing. 320037 00415587
DPI Correct file size reporting with DPI enabled for WhatsApp uploads Resolved an issue where file sizes and details were not accurately reported for files uploaded via WhatsApp when DPI was enabled. Reports now display correct file information and sizes as expected. 345145
EE Enforced Encryption deployment feedback improvement Previously, when attempting to deploy Enforced Encryption (EasyLock) on an EPP server with no EE client uploaded, users received a deployment notification but no feedback if installation failed. Now, the client displays a clear message if EasyLock cannot be deployed, improving user guidance in these scenarios. 403653
EE Immediate retrieval of Enforced Encryption settings on first ping Resolved an issue where the Enforced Encryption client received critical settings only after the second communication with the server. All relevant metadata is now updated promptly on the first ping across macOS and Windows EE. 409484

:double_exclamation_mark: The following versions may have limited or no support. Please see the Supported Version page for guidance.

2511.0 Updates

Endpoint Protector 2511 Client & Enforced Encryption Released

November 25, 2025

Component Description Case # Escalation #
General EPP Client to Server Communication Compression
In this release, we’ve introduced a Client to Server compression feature, which will be utilized in upcoming versions of EPP Servers (5.9.5.0 and higher) and Unify releases (7.4 and higher). This enhancement is designed to conserve bandwidth and reduce transfer limits on metered connections, as well as to lower costs associated with cloud providers.
382009, 382939, 383176 00437920
General Implemented Rate Limiting for OTP Verification
To enhance security, rate limiting has been added to the OTP verification process. Users entering 3 incorrect OTPs within a minute will have their attempts blocked for the following 5 minutes.
346608
General EPP Agent Updated with Netwrix Certificates
EPP Agent for Windows now supports new Netwrix signing certificates for integrity checks and validations.
362126
General Update Notifier Application Name
Replaced “Notifier Application” with “Netwrix Endpoint Protector Desktop Notifier” in all system tray and EPP Client notifications for a clearer and more complete identification.
385910
General Implementation of SID Field in Registration String
Added a new SID field to clearly separate it from the hostname, while retaining support for the existing hostname\sid format to ensure backward compatibility. Updates were made on both the client and server sides for consistent parsing and sanitization.
393887 00448448
General Enhanced OS Reporting with Compile Details
Updated EPP Client to provide comprehensive OS reporting details, including custom builds like “Oracle Linux” or “Mint Linux,” alongside the main distribution. Reports now show: main distro (self-report) → RHEL X.abc (Oracle abc). Standard reporting for plain RHEL/Ubuntu/Debian remains unchanged, ensuring detailed and accurate OS identification and reporting.
397551
General Entra ID Authentication Enhancement for Self-Remediation
Addressed authentication issues for customers using Entra ID with Self-Remediation and “Require Credentials” enabled. Enhanced functionality to fall back to interactive or network login when users lack the “Log on as a batch job” permission, resolving “Invalid credentials. (1385)” errors. This ensures seamless authentication flow even in cases where specific permissions are not granted, improving reliability and user experience.
400360
General Persistent Install Parameters During EPP Client/Server Upgrade
Improved upgrade process to ensure “IPV6MAPPING,” “SUPPRESSRD,” and “DISABLECAP” parameters persist seamlessly during EPP Client and Server Client upgrades.
402061 00448426
General Updated backend components to latest version
OpenSSL, PCRE,
402790, 387168
General Fix for High CPU Usage Due to CssGuard Service Issues
Addressed high CPU usage caused by cssguard service failures after EPP client upgrade, preventing the client from being uninstalled due to missing DLLs. Implemented a delay in service start attempts to resolve CPU core max-out situations.
389637
General Fixed Certificate Integrity Log Issue After Computer Name Change
Resolved problem where DPI certificate integrity failure logs were mistakenly generated due to a computer name change, not reflecting updated certificates in the certificate manager. Ensures no erroneous logs are produced when computer names are changed and services are restarted.
394605 00413365
General Improved Tamper Protection for EPP Client
Enhanced tamper protection for EPP Client to address vulnerabilities where it can be removed using Windows API calls, like “MoveFileEx,” with admin privileges. Additionally, ensured removal of related registry entries to prevent unauthorized uninstallation via “msiexec” or external software like Revo Uninstaller.
402710, 406056, 402231, 320104 00450947
General Fixed Blocking Issue for Apple Updates on EPP Mac Client
Resolved an issue where EPP Mac Client version 3.0.4.0 blocked Apple updates by interfering with device rights. Ensures updates proceed without disruptions after upgrading to the latest client version.
402197 00454951
General Fixed Issue with Notifier Start on Windows After Third-Party Tool Update
Resolved a problem where the EPP client Notifier failed to start for a standard user if installation was performed by an Administrator during a third-party tool update process while both were logged in. Ensures Notifier runs correctly for all users post-installation.
407830 00458093
DC Bluetooth Module Added to EPP Notifier on macOS
A Bluetooth module has been introduced to EPP Notifier for macOS to handle radio state change notifications.
358525
DC Monitor Mount Points Under /mnt on Linux
Added monitoring for file access on partitions mounted under /mnt, addressing customer needs for enhanced oversight
366972 00427257
DC Improved SD Card Reader Remediation
Enhanced handling of SD card reader connections: • No pop-up or “connected” log for empty readers. • Pop-up and logs (“Connected” and “Blocked”) appear when a card is inserted. • No “disconnected” log if only the card is removed; a log appears if the reader is disconnected.
400618 00441007, 00441004
DC Fix for Missing File Shadowing on Copy Events on macOS
Resolved an issue on macOS where file shadowing was missing for File Copy events to removable devices or network shares, ensuring shadows are now generated when file tracing and shadowing are enabled.
319851
DC Improved Remediation for Apple Magic Keyboard
Resolved issue where the Apple Magic Keyboard could not be properly remediated with User Remediation Pop-Up enabled. The keyboard now correctly registers remediation attempts when powered off and on, without persistent notification errors.
342260
DC Fix for OTP Validation Across Incorrect CAP and DC Tabs
Resolved an issue where an OTP used incorrectly in the DC tab invalidated it for the CAP tab, resulting in an “already used” message. The fix ensures OTPs retain validity for their intended use, allowing proper access granting in CAP after initial erroneous use.
359575
DC Detection Issue with Xerox Network Printers
EPP fails to detect Xerox network printers installed via Xerox software, displaying for Network device Property. Updates are needed to ensure accurate detection and integration of these printers in the EPP client.
385897
DC Fixed Inactive Self Remediate Button for MTP Devices
Addressed an issue where the Self Remediate button was inactive for MTP devices when connected with USB debugging enabled, even though remediation rights were set. This update ensures that the button is active and functional under the correct security settings.
388245
DC Adjustments for Transparent Mode Blocking
Resolved issues where switching to Transparent mode incorrectly blocked Bluetooth devices, audio drivers, and webcams. Ensures Bluetooth remains active for essential peripherals like mice and keyboards, while webcams and card readers are properly blocked.
389572 00445052
DC Fixed USB Detection Issue for BitLocker Encrypted Devices
Corrected improper usage of CoInitializeSecurity() affecting USB device detection for BitLocker encryption. Ensures the function is called correctly once per process, allowing proper USB access under TD Level 3 rights.
405562 00458188
DC Fixed Detection Issue for Wireless Voting Box USB Device
Resolved an issue where the EPP client failed to detect and manage access to a wireless voting box connected via USB. Ensures accurate detection and management under the Device Control system for affected endpoints.
405592 00430074
DC ** Fixed Issue with External DVD/CD-ROM Functionality**
Resolved an issue on Windows 11 where external DVD/CD-ROM devices failed to read newly inserted CDs after ejecting the previous disc. Ensures continuous functionality and proper access for the External DVD-ROM under specified EPP Client and Server versions.
408656 00460535
CAP Enhanced Detection of .CSV File Format
Improved the detection process for .CSV files to ensure they are accurately identified as CSV files, rather than being misinterpreted as plain text files. This enhancement addresses issues with the Restrict Content Detection setting, providing consistent recognition and reporting on the EPP server.
379179 00408710, 00453220
CAP Support for New File Formats in CAP and eD Policies
Added detection capabilities for .sbf, .pk, and .ddd file formats within CAP and eD policies to enhance file management and security protocols. Note: For full compatibility, an upcoming EPP Server 2512 or higher version will be required.
378583 327717
CAP Improved Brazil Phone Number Detection
Enhanced detection to accurately identify Brazilian phone numbers, including mobile and landline formats.
384232
CAP Improved Brazil address Detection
EPP now accurately detects and blocks partial Brazilian address formats making detection more useful for local standards and enhancing data leak prevention.
384313
CAP Updated US Passport PII Pattern
Enhanced recognition of US passport numbers to include a new biometric format introduced in 2021, consisting of a letter followed by eight digits, ensuring comprehensive detection alongside the older nine-digit format.
384243
CAP Native Box Drive Application Support
Implemented full CAP monitoring support for the native Box Drive application on Windows and macOS, replacing the retiring Box Sync to ensure seamless functionality.
388021
CAP Fix for Erroneous Folder Scans in EPP Client
Resolved issue where copying folders triggered errors due to the EPP client mistakenly scanning folder paths as file paths, resulting in blocked clipboard event handling. The fix ensures smooth folder copy operations without erroneous retries or thread blocking, applicable to all scenarios, including image monitoring settings.
388397
CAP Allowlist IPs Directly in Network Extension
Implemented configuration to ensure IPs that are allowlisted on the EPP server are also recognized by the Network Extension, preventing unnecessary interception and redirection. This update optimizes traffic handling by directly ignoring allowlisted IPs, improving efficiency while maintaining robust network security. Note: This applies only to IPs, not domains.
367786
CAP Fix for URL Blocking Issue with Facebook
Resolved URL blocking issue on Linux EPP client affecting Facebook. The solution involves adding Facebook IPs to the QUIC/UDP block list, forcing browsers to use TCP for successful interception and blockage. This ensures effective enforcement of denylist policies and reliable URL blocking.
392522 00448041
CAP Removed Unused “Send to EasyLock” Functionality
Eliminated the outdated “Send to EasyLock” option from the right-click context menu, addressing customer concerns by ensuring it no longer appears for users, streamlining interface experience for those not utilizing Enforced Encryption.
388648
CAP Fix for Google Cloud Platform Access Issue
Resolved issues where users experienced slow or failed access to Google Cloud Platform due to CAP events erroneously triggered by the Passports/US dataset. This fix ensures smooth login to GCP without unintended block policies, as confirmed by customer validation last week.
392646 00412160
CAP Fix for URL Blocking Issue with Facebook
Resolved Facebook URL blocking issue on EPP client for Linux by updating policies to ensure successful interception and enforcement of denylist rules.
392522 00448041
CAP OCR Support Enhancement for Ukrainian Language
Due to Microsoft’s OCR language limitations, EPP uses a workaround for Ukrainian OCR detection by leveraging the Russian language pack. When the system language is set to Ukrainian, the detection engine automatically utilizes Russian, provided the Russian language pack is installed, until native support becomes available.
394401 00448010
CAP Improved Visibility Over Opera Used Protocols
Enhanced control and monitoring by adjusting settings to improve visibility of protocols used by Opera, without compromising content inspection effectiveness.
406335
CAP Enhanced Blocking for Restricted Files in Google Drive
Fixed issues where restricted files were not consistently blocked in Google Drive. Ensured proper enforcement of CAP policies across Windows and macOS, improving reliability in blocking PII content.
319935
CAP Fix for Missing Logs and Shadows on Printed Files
Resolved an issue where File Transfer logs and shadows were not generated when printing embedded files from an Excel file under block and remediate policies. Ensured that both print attempts properly trigger FT logs and shadow creation, improving accurate reporting and remediation functionality. Further validation is recommended, especially when CAP policy is disabled, to ensure comprehensive fixes across scenarios.
320092
CAP Adjusted Printer Name Reporting in Remediation Events
Updated the Destination column in CAP Reports to display the correct printer name for Content Remediation Events, aligning it with the naming used in Content Threat Blocked events. This ensures consistent and accurate device identification across all event types in the reports.
320194
CAP Improved PII Blocking in Slack
Enhanced CAP policy enforcement to ensure files containing PII are effectively blocked in Slack, aligning with expected security protocols.
320197
CAP Improved File Blocking for GitHub Uploads
Resolved issue where files were not blocked when uploaded to GitHub, despite an active CAP policy. The solution ensures correct enforcement of file type and content restrictions set in the policy.
325564 00430839
CAP Improved Detection of .dxf AutoCAD Files
Enhanced Endpoint Protector to ensure both .dwf and .dxf AutoCAD files are detected and intercepted as per the Content Aware Policy,
327627 00409942, 00423115, 00410154
CAP Improved PII Detection and Blocking for Print Jobs
Resolved issues in which CAP policies failed to block print jobs containing PII in Excel files. The updated enforcement ensures threats are detected, reported, and appropriately blocked as expected.
341596
CAP Enhanced Threat Detection for Printing on Redirected Printers
Fixed the issue where CAP policies failed to detect threats when printing PDFs from Adobe Reader to redirected printers, particularly when scanning is set to ‘Per printed pages.’ Now, threats are correctly detected and print jobs are blocked as expected.
342381
CAP Resolved Sleep-Wake Issue Affecting PDF Printing Restrictions
Fixed an issue where a PDF that was previously blocked from printing would be allowed after waking the computer from sleep. The fix ensures that CAP policies consistently block such documents from printing without needing to refresh the tab or restart the browser.
346166
CAP Reduced Log Redundancy for Small File Uploads to Google Drive
Improved logging for files under 1MB uploaded to Google Drive, ensuring only one entry per threat is recorded in reports, rather than multiple (3-5) entries. This streamlines report accuracy and efficiency in threat monitoring.
346796
CAP Corrected Detection of New Outlook as Microsoft Teams
Fixed an issue where New Outlook was mistakenly identified as Microsoft Teams on Windows. The update ensures correct detection of Outlook, specifically for “outlook.office.com,” addressing misidentification reported in support cases.
364816, 364615, 361859, 364879 00424321, 00410015
CAP Fixed CAP Policy Application for Terminal Server Users
Corrected an issue where CAP policies were incorrectly applied to all users instead of the intended user when a machine was marked as a terminal server. The update ensures that CAP scenarios consider the actual user, providing accurately targeted policy enforcement.
365646 00412266
CAP Improved Website Reporting Accuracy for File Uploads
Fixed an issue where file uploads to certain websites, like Smartsheets and WeTransfer, incorrectly recorded as generic Amazon S3 sites in logs. The update ensures CAP reports accurately reflect the actual destination website details, providing clearer insights into file upload activities.
378240 00432792
CAP Fixed Blocking for Keynote (iWork) Files
Resolved an issue where Keynote (iWork) files were not blocked due to being detected as ZIP archives. The update ensures these files are correctly identified and blocked as per the CAP policy.
379815
CAP False Positives in Custom Content Dictionary
EPP incorrectly triggers false positives for longer words containing custom dictionary words during contextual detection, blocking content unnecessarily. Adjustments are needed to refine detection rules and eliminate these inaccuracies.
385848 00433082
CAP Transfer Limit Issue for CAP on Specific Sites
After reaching the CAP transfer limit, file uploads via sendspace.com or dlptest.com are still permitted, despite restriction settings. An update is required to enforce transfer limits correctly once reached.
386639
CAP Intermittent File Upload Allowance on Google Despite CAP Policy
Fixed a rare issue where file uploads on Google Mail and Drive were allowed despite CAP Policy, ensuring each request now has a unique key for consistent policy enforcement.
386804 00433965, 00456661, 00456592
CAP Inconsistent File Shadow Creation Despite Hash Generation
Addressed an issue where file shadows are not consistently created for files with generated hashes when copied from a shared network location to a local hard drive. This fix ensures Endpoint Protector reliably creates file shadows alongside hash generation, resolving inconsistencies observed in customer environments.
387222 00438809
CAP URL Blocking Issue in Slack Chat
Fixed an issue where URLs in https format sent via Slack chat were not blocked by CAP policies due to improper extraction of automatically converted URL tags. This update ensures URLs are correctly identified and blocked, preventing message transmission.
387303 00436293
CAP False Positive Blocking of Docx Files as XML
Resolved an issue where docx files were mistakenly blocked under CAP policies intended for XML files during transfer through monitored applications. The fix ensures accurate file identification and proper transfer permissions.
388023
CAP Fixed False CAP Reports for Single Character Clipboard Content
Resolved issue where single characters copied to the clipboard were falsely identified as “application/octet-stream” (Unidentified file type) in CAP reports. The fix prevents unnecessary triggers for clipboard monitoring policies.
388475
CAP Improved Consistency in Cloud Service Transfer Monitoring
Fixed issues with inconsistent scanning of file transfers to cloud services under CAP policies. This update ensures reliable monitoring and reporting across various exit points, including Google Drive, OneDrive, and FTP.
388719
CAP Fixed Inconsistent Blocking of Files on Fileport.io
Resolved an issue where CAP policies failed to block prohibited file types or PIIs during uploads on fileport.io through monitored browsers, despite DPI being enabled. Ensures consistent enforcement of blocking rules across all operating systems with recent EPP client versions.
388904 00446532
CAP Resolved False Positives from Background Requests on Multiple Websites
Addressed false positives triggered by background requests with “text/plain” content type when accessing websites like AWS, ChatGPT, EPFO, and GoDaddy under CAP policies. Also improved handling of “accounts.google.com” requests, reducing unnecessary notifications when opening Chrome on Google Search.
392521 00442439
CAP Fixed Blocking Configuration for Chrome Incognito and MS Edge
Updated CAP policy settings to correctly block Chrome Incognito and MS Edge using the specified application and command parameters, ensuring the blocking functionality is restored across Mac and Windows environments.
394034 00446648
CAP Fixed File Blocking Issue for Swisstransfer and Docusign
Resolved a problem where files sent through Swisstransfer and Docusign were not blocked by CAP policies with DPI enabled, ensuring consistent enforcement and blocking across all monitored services.
394035 00438663
CAP Fixed Label Detection in AIP-Encrypted Files
Corrected an issue where label detection failed for AIP-encrypted files due to improper conversion affecting negative values. Ensures accurate label extraction and blocking under CAP policy.
394600 00446976
CAP Fixed False Text/plain Threat Reports on dlptest.com
Resolved minor issue where CAP policies falsely reported text/plain threats when submitting a dummy Test Message on dlptest.com with DPI enabled. Ensures accurate threat detection across all operating systems.
395078
CAP Reduced False Positives for XML Files in Office Documents
Improved DPI and Extended source code detection to prevent default XML files within Office documents from being incorrectly reported by the EPP client, particularly for docx files. Most false positives are addressed, though some additional adjustments are forthcoming to eliminate duplicate XML reports entirely.
396194
CAP Fixed Duplicate Threat Reporting After Threshold
Resolved an issue where duplicate threats were incorrectly counted and reported after the threat threshold was reached in CAP policies. Ensures only unique threats are reported, maintaining accurate threat counts in both report-only and block&report policies.
396839 00450210
CAP Fixed Missing Justification in Remediation Logs for External Networks
Resolved issue where justification reasons for remediation actions were not logged when clients connected to external networks. Ensures that all remediation justifications are recorded and transmitted correctly once clients reconnect to the internal network.
397295 00450735
CAP Fixed Phone Number Blocking Issue in New Outlook
Resolved an inconsistency where files containing a single phone number entry were not blocked by CAP policies in New Outlook unless edited. Ensures consistent detection and blocking of phone numbers from Austria, US, and International formats, even with a single entry.
397983
CAP Improved Logging for Outlook Email Body in EPP
Adjusted logging behavior to exclude email body content from eppclient.log in release versions, preserving it only in debug builds. In production, we’ll log only the size of scanned content to confirm scanning has occurred, enhancing privacy and performance.
398176
CAP Fixed Logging Issue for Blocked Attachments in Outlook with Add-In
Resolved an issue on macOS where blocked email attachments based on file type were not logged and reported to the EPP server with the new Outlook add-in enabled. Ensures accurate server logging for blocked attachments in email communications.
398200
CAP Fixed ‘Report All Sensitive Data’ Issue for Outlook Attachments on macOS
Resolved an issue on macOS where the ‘Report all sensitive data’ feature did not function correctly for attachments blocked in Outlook due to file-related criteria. Ensures comprehensive reporting of both file type and sensitive content in such cases.
398214
CAP Fixed Scanning Issue for Outlook Attachments
Resolved a problem where Outlook attachments were not scanned when only the “Outlook (Attachments)” option was enabled in the CAP policy. Ensures emails with threatening attachments are correctly blocked.
401235 00455268
CAP Fixed File Upload Blocking Issue on Slack with DPI
Resolved an issue where the EPP Client failed to block file uploads and chat text in Slack when DPI was enabled, ensuring consistent application of blocking policies regardless of DPI status.
402123 00454703
CAP Addressed File Transfer Blocking Issue in Teams
Identified and resolved an issue where file transfers in Teams were not blocked.
402506
CAP Fixed File Upload Blocking Issue to Dropbox on Chrome on Linux
Resolved an issue preventing CAP policies from blocking file uploads to Dropbox through Google Chrome. Ensures proper enforcement and logging of file upload restrictions within specified policy settings on Linux environments.
404364 00452909
CAP Improved Detection of .CSV File Format
Enhanced the detection process to accurately interpret .CSV files, preventing them from being misrecognized as text files in the Restrict Content Detection setting. This update ensures .CSV files, including those using “;” as a separator, are correctly identified as CSV for reliable processing and security enforcement.
408311 00460230
DPI EPP Client Enhancement for Cisco Umbrella Compatibility
The EPP Client requires updates to monitor HTTP traffic routed through localhost:5002 by Cisco’s local proxy (csc_swgagent.exe) or Dope proxy and enable HTTP to HTTPS upgrades during DPI, as the current configuration does not allow this with a ClientHello message. Note: For full compatibility, an upcoming EPP Server 2512 or higher version will be required.
319881, 408016 00456102, 00453488
DPI Fix for Email Remediation with DPI Enabled
Addressed an issue where emails containing previously remediated threats were not being sent due to repeated threat detection when DPI was enabled. The fix allows emails to send successfully after remediation, ensuring consistent threat handling and resolution in the Mail app.
360576
DPI Enhanced Slack Reporting to Include Recipient Information
Resolved an issue where recipient information was missing from detailed Slack reporting logs. The update ensures that monitored PIIs are accurately reported with complete recipient details, providing comprehensive data in server logs for Slack communications.
364887, 365052, 378338
DPI Fixed DPI-Induced Network Access Issues in Chrome
Resolved a problem where DPI interfered with Chrome’s network access on systems with mixed IPv4-only and IPv6 adapters, causing connection errors. The update ensures correct identification and handling of IPv6 capabilities, preventing confusion and maintaining reliable network performance.
388793 00443875
DPI Fixed DPI False Positives Triggered by Chrome Updates
Resolved an issue where Google Chrome update checks erroneously triggered DPI false positives for text/xml file uploads under CAP policies. Ensures accurate monitoring without unintended reports during update checks.
392333
DPI Fixed False Positive Reporting on Dropbox with DPI Enabled
Resolved issue where the EPP client erroneously reported threats during interactions with dropbox.com when DPI was enabled. Ensures accurate monitoring without false positives across all operating systems.
397434
DPI Fixed Website Access Issues on Linux with DPI Enabled
Resolved an issue where the EPP client blocked access to multiple websites on Linux due to DPI Restricted app policy interference with localhost:(port). Ensures websites are accessible with DPI enabled and peer certificate validation active.
400994
DPI Resolved Excessive .tmp File Generation in Windows Temp Folder
Fixed issue where the EPP client continually generated and failed to clean up .tmp files in C:\Windows\Temp with Stealthy DPI enabled. Ensured proper cleanup mechanisms are in place to prevent file accumulation.
403682 00456221, 00416247, 00416478
DPI Improved Detection of Encrypted PDF Files in Outlook with DPI Enabled
Resolved an issue where encrypted PDF files within emails were not detected and blocked when DPI was enabled in Outlook. Implemented a reliable algorithm to identify encrypted PDFs by checking file accessibility and error codes, ensuring threats are appropriately intercepted and emails are not sent with such attachments.
405686
DPI Fixed File Upload Blocking Issue on bigconvert.11zon.com
Resolved an issue where CAP policies failed to block uploads of txt files containing PIIs or confidential information to https://bigconvert.11zon.com when DPI was enabled. Ensures consistent file upload blocking across browsers.
406059 00457381
DPI Enhanced Scanning and Blocking for WhatsApp Web (Beta)
Improved detection and blocking for sensitive files uploaded via WhatsApp Desktop (Beta), ensuring CAP policies effectively prevent unauthorized information sharing.
406176 00459072
eDiscovery Fixed Detection Issue in Predefined Scan Locations
Resolved an issue where the EPP Client failed to detect threats in predefined scan locations due to improper use of asterisks. The fix ensures accurate threat detection and reporting with correct scan path configurations.
346510
EE Improved EasyLock Deployment Feedback
Addressed issue where users receive misleading notifications when deploying EasyLock on a server without the EL client uploaded.
403653
EE Fixed Text Display Issue in Enforced Encryption on macOS
Resolved an issue where the password information text was cut off in Enforced Encryption on macOS, ensuring the full text displays properly in both the Setup Wizard and Password Dialog form, particularly when complex password requirements are enforced.
379392
EE Issue with Displaying New Items in Enforced Encryption
A bug prevents newly created items in the temporary folder from appearing in Enforced Encryption, even after refreshing. Fixes include enhancing automatic display of new items and correcting the ‘Refresh’ button functionality.
385764 00438605
EE Fixed EasyLock Launch Issue with TD1+ Read-Only Rights
Resolved a problem where EasyLock wouldn’t start from Windows Explorer when USB device rights were set to “Allow Access if Device is Trusted Level 1+ Otherwise Read-Only.” Ensures EasyLock launches successfully and modifies drive accessibility accordingly.
392261 00454746, 00439313
EE Fixed EasyLock Setup Wizard Display Issue on First USB Connection
Resolved an issue where the EasyLock setup wizard did not display upon the first USB connection when only the Windows EasyLock client was uploaded. The setup wizard now correctly appears as expected without needing to reconnect the USB.
395433
EE Fixed Auto-Update Issue for EasyLock on macOS
Resolved an issue where EasyLock version on macOS was not automatically updated when transitioning from server version 5.9.4.2 to 2509. Ensures consistent automatic updates, aligning macOS behavior with that of Windows systems for smooth server transitions.
397048
EE Fixed EasyLock Client Display Issue for Multiple USB Devices
Resolved an issue where deploying EasyLock on two different USB devices resulted in only the last deployed client appearing in the Enforced Encryption → Client lists on macOS. Ensures both USB1 and USB2 EasyLock clients are consistently displayed in the Client lists section.
403137

2509.4 Updates

Major Version Netwrix Enforced Encryption 2509.4.1.0 Released

October 14, 2025

Module Title & Description ADO Number Salesforce Number
EE New EE & Server Format Adjustments
Adjustment of EE Client versioning and alignment with new 2509.0.x.x EPP server interface
377746, 395433, 392614, 399908
EE Refreshed FIPS Validated engine
Refreshed FIPS engine component
375090
EE Minor Visual and Text Formatting Improvements 379392
EE Display Issue with Hidden Files on macOS Encrypted Panel
Implemented a solution to delete temporary files from the launch directory, depending on the drive format type.
398287
EE Updated EE Logo in Prompt
The pop-up for TD1+ RO should have the new logo.
388097
EE Enforced Encryption Launch Issue on TD1+ USB Devices
Resolved the issue where EE could not be started from Windows Explorer when USB devices were set to “Allow Access if Device is Trusted Level 1+ Otherwise Read-Only.”
392261

5.9 Updates

Version 5.9.4.3 Released (Now with Hotfix 1)

June 5, 2025

Component Description Case # Escalation #
General EPP Client to Server Communication Compression
In this release, we’ve introduced a Client to Server compression feature, which will be utilized in upcoming versions of EPP Servers (5.9.5.0 and higher) and Unify releases (7.4 and higher). This enhancement is designed to conserve bandwidth and reduce transfer limits on metered connections, as well as to lower costs associated with cloud providers.
382009, 382939, 383176 00437920
General User Remediation Challenge for Domain-Joined Devices Offline
This release addresses an issue where domain-joined Windows devices (connected to Active Directory) could not utilize user remediation for device control when disconnected from the network. Previously, attempting to authenticate with user credentials after disconnecting from the network resulted in an “Invalid credentials. Couldn’t initialize the connection.” error. This has been optimized to ensure seamless authentication, allowing users to access connected USB devices even when offline.
384611 00437637
General Enhancement to EPP Client Behavior on Ubuntu Xorg
We’ve refined the login process on Ubuntu Xorg (version 24.04) to prevent the EPP client window from opening automatically without user initiation, ensuring a more seamless user experience. Additionally, options accessed via the right-click menu now appear as intended, enhancing usability.
385428 00435662
General Resolution for Department Reverting Issue in EPP Client Upgrade
Upgrading the EPP client to version 6.2.4.2000 or higher previously caused departments to default to “defdep” due to a re-registration process triggered by an OpenSSL upgrade. This update ensures that custom department settings are retained during client upgrades, whether performed manually or via server updates, maintaining organizational consistency.
379516 00437612, 00437246
General Improved Client Termination Logging During Node Maintenance
The update refines handling to prevent unintended termination logs during node maintenance. This ensures smooth node transitions without triggering “Unplanned Client Termination” or “Forced Uninstall Attempt” logs.
380237 00436395
DC Improvement in Bluetooth Device Classification for Access Rights
The update enhances the accuracy of device classification, addressing situations where Bluetooth headphones previously detected as “Bluetooth Other” by older EPP agents are assigned incorrect access rights upon upgrading. Now, devices identified as “Bluetooth Headphone” will consistently receive the appropriate permissions, reflecting improved device categorization and resolving mismatches in access rights application.
369454 00423693, 00424784
DC Enhanced Linux Bluetooth Control via DBus Events
We have reworked the handling of Linux Bluetooth permissions to leverage DBus events, significantly enhancing the ability to control Bluetooth devices on Linux. This change improves precision and flexibility in managing Bluetooth connections and device interactions within the Linux environment.
377022, 385745
DC Improved Management of Bluetooth Pop-Ups on macOS
Adjustments have been made to ensure that Bluetooth pop-ups are properly displayed only when appropriate permissions are in place. This enhancement ensures that the EPP agent requires full disk access to modify local databases, preventing unnecessary pop-ups if permissions are not granted, thereby streamlining user interaction on macOS.
370581 00423432
DC Streamlined Log Generation for iPhone Connections
Improvements have been implemented to ensure log entries are generated only once when connecting or disconnecting iPhones, preventing duplicate entries. This update enhances clarity and accuracy, reflecting actions performed with devices set to “Deny” permissions, optimizing log management in the specified environment.
371529
DC Improved File Tracing for Write Events
Enhancements have been made to ensure that the EPP client consistently captures File-Write and Read-Write events on network shares and removable devices. Previously, certain file changes, such as edits and saves made using Notepad, Notepad++, or Visual Studio, might not trigger events as expected. This update refines the File Tracing process, increasing the reliability of event detection on Windows for diverse editing applications.
374320
DC Resolution for Ignored File Size Limit in Shadowing
The EPP system has been updated to respect the “Max File Size for Shadowing (KB)” setting, ensuring files exceeding the set limit are not shadowed on macOS systems running Sequoia and above. Previous behavior allowed oversized files to be shadowed and sent to S3 buckets despite size constraints. This enhancement restores expected functionality for effective file management and compliance.
375226 00431461
DC Enhanced Detection for ASIX Ethernet Adapters on macOS
The EPP client now accurately identifies ASIX Ethernet adapters as wired connections, ensuring that Wi-Fi is blocked when these adapters are in use. This improvement uses name detection for ASIX devices to correctly categorize the connection type, providing consistent enforcement of Wi-Fi denial policies on macOS systems.
375955 00434222
DC Improved Detection of Teensy Board Devices on Windows
This update refines device identification by limiting detection to specific VIDs, ensuring more accurate classification of Teensy boards. It corrects previous misclassifications on Windows, such as identifying certain adapters as Teensy boards, and aligns detection more closely with intended device types.
375964 00434607
DC Enhanced Network Printer Recognition by EPP Client
The latest update improves the recognition of network printers by the EPP Client on Windows 10, ensuring seamless identification and integration within the network environment.
375227 00436900
DC Enhanced WiFi Blocking on Linux
The update ensures WiFi is consistently blocked upon policy changes or reactivation without needing a service restart, enhancing enforcement on Ubuntu 22.04 systems.
376531 00435378
DC Restoration of “Deny-Access but Allow Charging” Functionality
The update addresses an issue in version 5.9.4.1 where the “Deny-Access but Allow Charging” setting unintentionally blocked iOS devices, hindering charging. The functionality is restored to ensure devices are not blocked while allowing charging as intended.
377456 00418020
DC Enhanced File Shadowing for Names with Special Characters
Updates have been implemented to ensure files with whitespaces or special characters in their names are successfully uploaded to an FTP server as part of the file shadow repository. Improvements in handling file URL formatting address prior errors, ensuring seamless file tracing and shadowing on Windows systems.
380898
DC Improved Remediation for Logitech MX Master Mouse
Enhancements have been applied to ensure a stable remediation session for the Logitech MX Master Bluetooth mouse. Users will no longer experience intermittent blocking and notifications, allowing uninterrupted use during active remediation sessions with Device Remediation enabled for Bluetooth Mice.
381996
DC Correction of File Tracing Events on macOS
This update refines file tracing for text file edits on macOS, ensuring proper event logging. Previously, edits on removable devices or network shares could lead to incomplete logs. Now, file activities are consistently captured and reported.
384396
DC Resolution for Mountain Duck Accessibility
The update addresses issues where Mountain Duck cloud drive was blocked by EPP settings for “Unknown Devices.” Now, Mountain Duck can start and function properly without errors, even with restrictive device policies in place.
384518 00437196
DC Adjustment for Handling Multiple Printers with the Same Name
This update resolves issues where network printers with identical names were not consistently blocked in Safari when disabled in DC. The system now ensures that all instances of the same printer are correctly recognized and restricted, preventing unauthorized printing.
384608
DC Improved Enforcement of Bluetooth Permissions on Ubuntu 22.04
The update ensures that Bluetooth permission settings are adhered to on Ubuntu 22.04, preventing manual enablement of Bluetooth devices when permissions are set to Deny.
385745
CAP Improve Detection of Brazilian PIIs
We’ve improved the detection of Brazilian Personally Identifiable Information (PII) by differentiating between CPF and CNH patterns. Due to excess noise generated by CNH, CPF has been separated into its own selectable pattern within CAP/eD policies. Customers will need to manually adjust their CAP/eD policy definitions to accommodate this change and align with their specific requirements. Note: This update requires at least version 5.9.4.2 of the EPP Server and version 5.9.4.3 of the EPP Clients.
342068, 320008, 376836 00419481
CAP Suppress Windows Notifications When Copying to USB
To enhance user experience, we have suppressed Windows notifications that prompted users to Skip, Replace, or Cancel during file copying to USB drives when blocked by a CAP policy. Previously, these notifications could be disruptive, especially when multiple files were copied at once. This improvement ensures a smoother interaction by eliminating the need for user intervention in such scenarios.
343859
CAP Stop Monitoring XDG Desktop Portals Except for Ubuntu 18.04
We have refined our monitoring processes to reduce unnecessary log noise by ceasing to monitor xdg-desktop-portal* for file access on all systems except Ubuntu 18.04. On Ubuntu 18.04, we will continue to monitor xdg-desktop-portal-gtk to effectively capture file access events, particularly for file pickers used by applications like web browsers. Known Limitation: For Ubuntu versions 18.04, 20.04, 22.04, and 24.04, when using Firefox browsers to navigate through files, the EPP Client may generate false positives.
367650 00433696, 00427782
CAP Proxy Configuration Management in Endpoint Protector
This update ensures that the proxy configuration is accurately reflected post-upgrade, allowing users to disable or adjust proxy settings without residual entries that could affect performance. Users making this transition should now find a smoother experience in adjusting their network configurations according to the new settings.
371451 00427365
CAP Improved File Scanning for Google Translate Uploads
We are addressing the handling of file uploads to Google Translate, enhancing our scanning process to ensure data protection. Currently, limited file types such as .docx, .pdf, .pptx, .xlsx, and images are supported for upload and translation.
374645 00434813, 00435082
CAP Resolution of False Positive US SSN Detection in PDF Printing
We have addressed an issue where false positives for US Social Security Numbers (SSN) were detected when printing threat-free PDFs from OneDrive Business using browser menu options. This release enhances the detection algorithms to mitigate false alarms, ensuring that print jobs proceed smoothly without unnecessary interruptions.
339356 00431461
CAP Resolution of False Positive US SSN Detection in Webpage Printing
We have addressed a regression issue where false positives for US Social Security Numbers (SSN) were detected while attempting to print threat-free webpages from browsers like Edge and Chrome. This update refines the detection process, ensuring webpages without sensitive data can be printed successfully without being erroneously flagged by CAP policies.
339390
CAP Improved Monitoring of New Microsoft Teams File Transfer on Windows
This update enhances the EPP client’s ability to monitor and control file transfers in the New Microsoft Teams on Windows. With improved visibility, the EPP client effectively intercepts and manages file transfers, ensuring they are appropriately monitored and controlled even when DPI is disabled.
340606 0042295, 00417651
CAP Improved Monitoring for Microsoft Teams on Linux
Enhanced the EPP client’s ability to monitor Microsoft Teams activity on Linux. This update ensures that the "teams " process is properly tracked, allowing file transfers to adhere to CAP policies and improving overall compliance with monitoring requirements.
347077
CAP Refined Identification of Microsoft Teams and Slack Traffic with Proxy Usage
An enhancement has been made to accurately distinguish network traffic originating from Microsoft Teams and Slack from that of Chrome when a third-party proxy, like Sophos, is used. Previous configurations led to all traffic being routed through the proxy being incorrectly identified as Chrome, causing scanning irrespective of CAP policy settings.
369085
CAP Improved Functionality for Safari Browser in Xcode Simulator
This update enhances functionality for the Safari Browser in Xcode Simulator on macOS when DPI is enabled. It ensures that webpages load correctly, providing a seamless browsing experience in the simulator environment regardless of the “Intercept VPN Traffic” setting.
343756 00411657
CAP Enhanced Blocking for Print Screen on Windows 11
This update addresses the issue where the EPP client did not consistently block the print screen functionality on Windows 11 for certain key combinations. The enhancement ensures that all defined scenarios within CAP policies, including Fn+PrintScreen and PrintScreen alone, are effectively blocked, maintaining compliance and security on Windows 11 systems.
364964
CAP Blocking SnippingTool on Windows 11 with CAP Policy
Enhanced CAP policy capabilities to effectively block the SnippingTool executable on Windows 11 when the print screen function is selected.
367687 00438810, 00426022
CAP Enhanced Stability for Print Screen Blocking
The EPP agent has been updated to address issues where print screen functionality might not be consistently blocked due to multithreading complications. By refining the policy loading process to ensure flags are set accurately across threads, print screen operations are now reliably controlled, maintaining security expectations for both Windows 10 and Windows 11 environments.
373916 00426022
CAP Resolution for Incorrect File Type Reporting in Image Transfers
This update enhances the monitoring of files transferred via Airdrop using Drag and Drop on macOS. By implementing a dynamic detection mechanism for temporary file paths, the EPP agent ensures that files are accurately scanned and sensitive data is effectively blocked during transfer using this method.
367340
CAP Enhanced Airdrop File Blocking for Drag and Drop Actions
The EPP agent now better monitors files sent via Airdrop using Drag and Drop on macOS. Through dynamic detection of temporary file paths, files are scanned, and sensitive data is effectively blocked during transfer.
367530 00426475
CAP Custom Content Denylist for Korea
The CAP policy for Korean custom content now effectively blocks files sent via browsers. This update ensures accurate detection and blocking of Korean-language files.
368220 00419610
CAP Improved Scanning for swisstransfer.com Data Transfers
The EPP agent has been updated to ensure accurate scanning of data sent via swisstransfer.com.
368729 00429663
CAP Enhanced Policy Enforcement with OCR Configuration
The policy enforcement has been improved to ensure that image files are accurately blocked by the EPP client when OCR is enabled, regardless of the content. This refinement addresses previous limitations by allowing stricter adherence to image blocking policies without relying solely on detected text content.
370034
CAP Stability Enhancement for Ubuntu 18.04 Linux Clients Handling File System Events
Enhancements have been made to prevent crashes in Linux clients when generating a large number of file system events. Implementing a thread pool addresses the issue of reaching thread count limits, ensuring system stability while handling extensive file operations on removable devices. This improvement optimizes performance and reliability on Ubuntu 18.04.
371646 00432785
CAP Resolution for Application Denylist Parameters
The application denylist has been refined to ensure consistent operation regardless of parameter case sensitivity. Previously, rules with uppercase command line arguments were ineffective, but this update ensures applications are properly blocked irrespective of parameter casing. The fix applies to both Windows and macOS environments, enhancing reliability and functionality in diverse setups.
373725
CAP Resolution of File Shadowing Issue with Printer Names
The EPP system now supports file shadowing for CAP policies irrespective of the characters used in printer names. Previously, special characters like “:” in "http://10.0.1.10 could block shadow creation, compromising the handling of confidential content. This update ensures consistent shadowing functionality, accommodating complex printer names without disrupting operations.
374363 00427161
CAP Enhanced Stability for EPP Client on macOS
The update addresses EPP client crashes during app control by improving the handling of multiple security events. By optimizing message processing, the client now operates smoothly without interruptions when utilizing CAP policies to block applications on macOS.
374276 00428724
CAP Resolution of CAP File Shadowing Issue
The update ensures images are properly shadowed according to CAP policies, addressing previous issues where JPEG uploads were not shadowed despite monitoring on macOS and Linux environments.
376510 00426339
CAP Enhanced Clipboard Image Blocking on Windows
The update ensures clipboard images are blocked effectively under CAP policies on Windows 10 and 11, resolving prior inconsistencies when reporting sensitive information.
376539
CAP Enhanced Git Upload Blocking on macOS
The update addresses the ability to block uploads to “GitHub” using the native Git application on macOS when “Intercept VPN Traffic” is enabled in DPI. This ensures commands over HTTP remotes are effectively restricted under CAP policies.
377208 00430839
CAP Enhanced Regex Functionality in CAP Policies
The latest update resolves issues where not all regex patterns were applied in CAP policies, leading to unblocked transfers. The EPP client now consistently applies multiple regex patterns as defined by administrators, ensuring all relevant transfers are properly monitored and blocked when conditions are met.
380070 00438983
CAP Enhanced Stability for Notifier Under Clipboard Spam
Improvements have been made to ensure the Notifier maintains stability even when subjected to excessive clipboard copy commands. The update prevents freezing, ensuring smooth functionality when clipboard filtering policies are active on Ubuntu 22.04 with recent client versions.
380341 00435758
CAP Correction for CAP Report Item Count Accuracy
An update has been applied to accurately reflect item counts in CAP reports, ensuring reported logs match the set policy criteria. This resolves discrepancies where fewer items appeared than expected, aligning displayed counts with actual detection results.
380525 00427620
CAP Reduction of False Positives for Rippling.com
Enhancements have been made to CAP policy configurations to significantly reduce false positive threat reports while browsing rippling.com. Adjustments improve the accuracy of detection for personal and sensitive data, ensuring more reliable results.
380588
CAP Improved Regex Support for International Characters
This enhancement ensures that content with international symbols, such as Chinese characters, is accurately matched against defined regular expressions, addressing customer concerns.
382013 00440150
CAP Resolution for Google Meet Performance Issues on macOS
Enhancements have been made to address performance issues in Google Meet sessions on macOS, ensuring smooth connectivity and functionality for video and audio.
382020 00429561
CAP Resolution for Slowness in WebStorm Application
Adjustments have been made to CAP policy settings to address slowness experienced in WebStorm and PyCharm applications. The issue was linked to the network share exit point; modifying these settings ensures normal application performance without compromising functionality.
385321 00437363
CAP Printing Delay Issue Resolved in Special Browser Pages
Fixed a printing delay issue where the “Block Print from Browsers” feature caused hangs when printing from special Chrome pages. This update ensures prompt printing on Windows with Edge or Chrome browsers.
388233 00445778
DPI Reduction of DPI False Positives Related to Cloudflare
The update refines DPI scanning to reduce false positives when browsing websites utilizing Cloudflare security measures like bot detection and CAPTCHA. It ensures more accurate monitoring, preventing unnecessary reports during routine navigation on various websites.
384498
DPI Enhancement to DPI with “Intercept VPN Traffic” Capability on macOS
Addressed a limitation where DPI with “Intercept VPN Traffic” could not inspect network traffic for unsigned applications run from non-standard locations on macOS due to sandboxing restrictions. The update improves DPI’s ability to better manage applications launched from non-standard directories, though it may still face challenges without full permissions. Users are encouraged to maintain standard application paths to ensure proper functionality.
DPI Improved Enforcement for DPI Restricted Apps
The update strengthens DPI controls by ensuring that the “Bypass DPI Certificate Rejection by Third-Party Applications” setting does not apply to DPI-restricted apps like Git. This enhancement prevents unauthorized uploads to Git repositories with untrusted certificates, aligning functionality with CAP policies to consistently restrict intended operations.
369796 00430839
DPI Reduction of False Positives in Google Meet Sessions
This update refines DPI functionality to prevent false positive alerts during Google Meet WebRTC sessions, ensuring accurate detection and reducing unnecessary noise in CAP policies configured for Brazil PII.
378052 00423343
DPI Enhanced Scanning of File Uploads to m365.cloud.microsoft
The update improves DPI capabilities to scan and assess files uploaded to m365.cloud.microsoft, specifically targeting requests to graph.microsoft.com with URIs containing /drive/. This enhancement ensures sensitive data is detected and appropriately blocked during uploads from the HOME page, refining CAP policy enforcement for browser-monitored activities.
384336 00442443
General HOTFIX: EPP Client Version 6.2.5.1004 Crash During Upgrade
Upgrading the EPP Client to version 6.2.5.1004 might result in a crash of EPPnotifier.exe due to a missing Microsoft redistributable DLL, causing the client to become unusable.
395207 00449020, 00448903
CAP HOTFIX: Netwrix Data Classification: PDF Tag Support Issue
Fixing issue with the Netwrix Data Classification tags within PDFs were not extracted correctly.
349046 00429414

Version 5.9.4.2 Released

April 3, 2025

Component Description Case # Escalation #
Security Security fixes
This release contains important security fixes for EE. For information on these security fixes, please visit this security advisory. All EE customers are advised to update.
376907, 376911, 376835
Security Endpoint Protector Server Back End Components Refreshed
Upgraded backend components for JQuery
3788110 431347
General Re-enabling license management on Netwrix hosted environment
License management functionality has been restored in the Netwrix-hosted environment
377943
General Fix “Transfer Limit” alert not to be sent to the deleted administrators
Adjusted system configuration, now only the available administrator receives the Transfer Limit Alert. This targeted notification approach ensures timely and relevant updates are delivered to the appropriate personnel, streamlining alert management and response.
344718 411953
General Alerts cache is not recreated properly
Resolved an issue with the alert caching system, where updates made to a CAP alert involving changes to selected computers and users were not properly reflected in the cache. Previously, editing an alert to uncheck or check machines did not result in a correctly rebuilt cache. With this fix, the alert cache will now be accurately regenerated to include all specified machines and users after any modifications.
319858 416406, 409790
General Ensuring Proper Cache Regeneration After Alert Renaming
Fixed an issue where renaming an alert did not trigger the proper regeneration of the cache, leading to outdated or inaccurate information being displayed. With this update, whenever an alert is renamed, the system will now correctly regenerate the cache to ensure all data is current and reliable.
348301 416406
General Correct Email Address Display in Alert History
Resolved an issue where the wrong email addresses were being displayed in the Alert History under Alert Details: Recipient across all alert types. This occurred when an alert was created using the “Check All” option in the Administrator section, which included deleted administrators. With this fix, the system now accurately displays the correct email addresses associated with active administrators in the Alert History.
364793, 366029 426144
General Group selector improvement
Enhanced the functionality within the Computers and Users tables to ensure that selected items remain checked even after clicking the “select all” checkbox while using the search filter.
358129 356518
General Improved Responsiveness of Dashboard Text
Addressed an issue where the text under the Modules section on the General Dashboard was not responsive, causing it to be overlapped by the Most Active Users section when the browser width was reduced to less than 1880px. With this update, the text is now fully responsive, ensuring clear and unobstructed display across all screen sizes.
319927
Device Control Reliable Computer Name Updates for Mac and Windows
Resolved an issue affecting both Mac and Windows computers, where changes to the computer name were not being permanently applied. With this update, any computer name edits are now consistently saved and accurately reflected in the Computer List, ensuring reliable updates across both platforms.
319856
Device Control Correct Handling of Serial Numbers with “&” in Custom Classes
Resolved an issue where adding devices to Custom Classes using the Bulk Import or New Device options resulted in incorrect handling of serial numbers containing the “&” character. This led to improper saving of these devices and misapplication of device rights. With this fix, serial numbers with “&” characters are now correctly processed, ensuring accurate saving and application of device rights.
370345 430816
Content Aware Protection Results are not sorted when using specific filter in CAP reports
Improved sorting and filtering capabilities to allow results to be organized according to any specified column.
351200 351168
Content Aware Protection MPIP reporting details
We’ve refined the reporting details for the Content Remediation Session Active log. Now, the ‘Items Type’ column prominently displays the ‘MIP Classification,’ offering clearer insight and a more organized view of your data management activities.
355766
Content Aware Protection Denylists/Allowlists dictionaries import
Resolved an issue where an invalid .xls file import would incorrectly create a dictionary despite showing an error message. Now, the error “Import failed! Please use a valid .xls file!” will be displayed, and no dictionary will be created, ensuring accurate data handling and user notifications.
359542
Content Aware Protection Resolved Export Issue in Denylists/Allowlists Sections
Addressed a problem affecting the export functionality in the Denylists/Allowlists sections, where exporting a dictionary containing 50,000 items would result in a “no results” message upon opening the file. This issue has been resolved, and exports will now correctly display all items as expected.
359501
Content Aware Protection Fixed Misidentification of Microsoft Outlook as Microsoft Teams by Endpoint Protector Client
Resolved the issue where the Endpoint Protector Client was incorrectly identifying Microsoft Outlook as Microsoft Teams. With this fix, Microsoft Outlook is now properly recognized, ensuring accurate monitoring and protection for the correct application
367917
Enforced Encryption Enhanced Security for Offline File Tracing with Enforced Encryption
We’ve enhanced the security of our Enforced Encryption feature, specifically when configured for “Offline File Tracing.” With this update, file encrypt/decrypt events are now securely encrypted, ensuring that offline file tracing events are uploaded to the server only after the user logs into Enforced Encryption (EE) with their password.
362675

Version 5.9.4 Released

December 12, 2024

See the Endpoint Protector 5.9.4 Bug Fix List for a list of bugs fixed in this version.