cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
TechTop
Level 7
Report Inappropriate Content
Message 1 of 4

Endpoint Security Threat Prevention blocks Windows 10 22H2 CU Update

Hi community, i am new here, 

Endpoint Security Threat Prevention is blocking Win 10 22H2 CU Update . The attempt always ends with error. As soon as onscan is deactivated in the EPO server, the update can be carried out. Is there a solution to this? We control the ENS via an EPO server and have around 200 clients. Thanks in advance.

 

3 Replies
hnegishi
Employee
Employee
Report Inappropriate Content
Message 2 of 4

Re: Endpoint Security Threat Prevention blocks Windows 10 22H2 CU Update

Hi @TechTop 

Thank you for reaching out to our community.

We support Win 10 22H2 with following ENS version. 

ENS 10.7.0 June 2022 Update, 10.7.0 November 2022 Update, 10.7.0 April 2023 Update

You can check the ENS build number with following article.

Supported platforms for Endpoint Security (trellix.com)

Please check the build number on your client systems in ePO system tree.

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
TechTop
Level 7
Report Inappropriate Content
Message 3 of 4

Re: Endpoint Security Threat Prevention blocks Windows 10 22H2 CU Update

Hi hnegishi, 

thanks a lot for your response, we have deployed ENS 10.7.0 November 2022, the problem still persist. 

However, we can't do the CU22H2 until we disable or uninstall ENS. What else could it be? unfortunately we have not found a solution for this. 

Thanks

 

ueno
Employee
Employee
Report Inappropriate Content
Message 4 of 4

Re: Endpoint Security Threat Prevention blocks Windows 10 22H2 CU Update

Hi @TechTop,

It is possible that the root certificate required by ENS is missing, and that during the Windows OS update, the Windows OS module was mistakenly determined to be malware and blocked by the on-access scan.

If possible, please check if the behavior improves once you add the root certificate using the file attached in the KB below.

[Product install or upgrade issues due to missing root certificates]
https://kcm.trellix.com/corporate/index?page=content&id=KB87096

<Example of procedure for adding a root certificate
1. download the file "2023_Certificates.bat.txt" in KB87096.
2. Change the extension of the .bat.txt file to .bat, start the command prompt as an administrator and execute the .bat file.
*Please note that if you do not run as an administrator, the addition of the certificate will fail.
*It is not necessary to restart the OS after adding the root certificate.

After adding the root certificate, please execute the following command to clear the cache just in case.

>C:\Program Files\Common Files\McAfee\SystemCore\vtpinfo.exe /resetvtpcache

If you are still blocked by the on-access scan after that, please contact us with a service request, as it is difficult for us to answer in the community.

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community