> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/7.x/7.4-eol/addressed-issues-in-cortex-r-xdr-tm-agent-7.4.md).

# Addressed Issues in Cortex® XDR™ Agent 7.4

* [Addressed Issues in Cortex XDR Agent 7.4.4](#addressed-issues-in-cortex-xdr-agent-744)
* [Addressed Issues in Cortex XDR Agent 7.4.3-hotfix](#addressed-issues-in-cortex-xdr-agent-743-hotfix)
* [Addressed Issues in Cortex XDR Agent 7.4.3](#addressed-issues-in-cortex-xdr-agent-743)
* [Addressed Issues in Cortex XDR Agent 7.4.2](#addressed-issues-in-cortex-xdr-agent-742)
* [Addressed Issues in Cortex XDR Agent 7.4.1](#addressed-issues-in-cortex-xdr-agent-741)
* [Addressed Issues in Cortex XDR Agent 7.4](#addressed-issues-in-cortex-xdr-agent-74)

### Addressed Issues in Cortex XDR Agent 7.4.4

The following table details addressed issues in Cortex XDR agent 7.4.4.

#### Feature

CPATR-15441

#### Description

Fixed an issue where the agent is using a large amount of disk space.

#### Feature

CPATR-15441

(Windows)

#### Description

Fixed an issue where the agent is using a large amount of disk space.

#### Feature

CPATR-15252 (Windows), CPATR-14737

#### Description

Fixed an issue where querying for hardware ID changes on an endpoint, NULL values are ignored.

#### Feature

CPATR-14804

(Windows)

#### Description

Fixed an issue where external USB drives scans are inconsistent with scan configuration.

#### Feature

CPATR-14729

(Windows)

#### Description

Fixed an issue where some processes may crash while the DLL Security module is enabled.

#### Feature

CPATR-14790

(MacOS)

#### Description

Fixed an issue where local analysis module preventions are reported with the wrong Incident ID on macOS Catalina impacting incident generation.

#### Feature

CPATR-14788

#### Description

Fixed an issue where agent proxy settings are incorrectly stored causing endpoints to become disconnected.

#### Feature

CPATR-14717

#### Description

Fixed an issue where the IP allow list may not always be applied correctly.

#### Feature

CPATR-14801

#### Description

Fixed an issue where updated WildFire verdict is not stored on the agent.

#### Feature

CPATR-14678

#### Description

Fixed an issue where an agent might fail to cancel a scan if it has reached a time-out while the agent was not running (stopped).

#### Feature

CPATR-14647

#### Description

Fixed an issue where there was no message of successful upgrade to the current agent version.

#### Feature

CPATR-14726

#### Description

Fixed an issue where a malware scan does not show the correct status when performing a reset.

### Addressed Issues in Cortex XDR Agent 7.4.3-hotfix

The following has been addressed in this release for build numbers:

Windows - 7.4.3.40287

Mac - 7.4.3.2228

Linux - 7.4.3.39946

#### Feature

CPATR-14895

#### Description

Fixed an issue where Cortex XDR agents running without trusting certificates “GlobalSign Root CA” may encounter issues downloading upgrade packages and content updates, and may also affect large scans verdict retrieval.

### Addressed Issues in Cortex XDR Agent 7.4.3

The following table details addressed issues in Cortex XDR agent 7.4.3.

#### Issue ID

CPATR-14151

#### Description

Fixed an issue where a missing user or MDM configuration might cause an unknown content filter state, resulting in the loss of network events and in network-related features not working.

#### Issue ID

CPATR-14240

#### Description

Fixed an issue where requests to load or unload extensions might fail with an unknown error (OSSystemExtensionErrorDomain error 1, unknownError), and the request was not repeated.

#### Issue ID

CPATR-14243

#### Description

Fixed an issue where a country flag and name were displayed, instead of the country language.

#### Issue ID

CPATR-14333

#### Description

Fixed an issue where syscall provider names that did not follow a file path naming structure might cause Windows performance counter APIs to fail.

#### Issue ID

CPATR-14420

(MacOS)

#### Description

Fixed an issue where no additional attempts were made to load or unload a MAC extension if it failed due to an unknown error.

#### Issue ID

CPATR-14430

#### Description

Fixed an issue where Office macros might cause repeated uploads of the same file to WildFire if that file was successfully uploaded at least once by TUS.

#### Issue ID

CPATR-14445

#### Description

Fixed an issue where file uploads unnecessarily consumed network traffic when the upload quota was surpassed.

#### Issue ID

CPATR-14560

(Windows)

#### Description

Fixed an issue where the Cortex XDR agent might lose connectivity to the server if the endpoint network location was changed frequently.

#### Issue ID

CPATR-14568

(MacOS)

#### Description

Fixed an issue where an unknown old WildFire verdict might not trigger a request for an expired verdict.

#### Issue ID

CPATR-14687

#### Description

Fixed an issue where alerts, already categorized as exceptions, might be triggered.

#### Issue ID

CPATR-14700

(Windows)

#### Description

Fixed a compatibility issue in Citrix App Layering in which endpoints might fail to register.

### Addressed Issues in Cortex XDR Agent 7.4.2

There are no addressed issues in this release.

### Addressed Issues in Cortex XDR Agent 7.4.1

The following table details addressed issues in Cortex XDR agent 7.4.1.

#### Issue ID

CPATR-14107

(Windows)

#### Description

Palo Alto Networks strongly recommends that you upgrade your operating system as soon as possible and follow Microsoft Security Advisory statement regarding vulnerabilities CVE-2021-1675 and CVE-2021-34527.

For Cortex XDR agents running on unpatched Windows endpoints, the Behavioral Threat Protection (BTP) module will detect and terminate the malicious attack when there is an attempt to exploit CVE-2021-1675 and CVE-2021-34527. On non-vulnerable endpoints, Cortex XDR will report the malicious attack.

#### Issue ID

CPATR-14014

#### Description

Fixed an issue where updating the verdict of a file to Benign with Low Confidence for the second time failed.

#### Issue ID

CPATR-14005

(Windows)

#### Description

Fixed an issue where renaming the Content library failed on endpoints integrated with Citrix AppLayering.

#### Issue ID

CPATR-13951

(Windows)

#### Description

Fixed an issue where recursive filesystem calls could cause the endpoint to halt.

#### Issue ID

CPATR-13898

(Windows)

#### Description

Fixed an issue on endpoints with 3rd party solutions using a proprietary file system, where the endpoint could suddenly halt.

#### Issue ID

CPATR-13855

#### Description

Fixed an issue where after upgrading the Cortex XDR agent to the 7.4.0 release, the scan of a hash with a Benign verdict could timeout.

#### Issue ID

CPATR-13851

#### Description

Fixed an issue where after you added an unknown hash to the Cortex XDR Allow List, if later WildFire returned a Malware verdict, then post detection alerts were generated.

#### Issue ID

CPATR-13850

#### Description

Fixed an issue where if the first attempt to upgrade a Cortex XDR agent 7.4.0.X to a newer release failed, then all subsequent upgrade attempts failed as well.

#### Issue ID

CPATR-13789

(Windows)

#### Description

Fixed a compatibility issue with the ROP Mitigation module running on 64-bit architecture.

#### Issue ID

CPATR-13750

(Windows)

#### Description

Fixed an issue on Windows file servers 2012, where after upgrading the Cortex XDR agent to the 7.4.0 release, the endpoint could reboot on rare occasions.

#### Issue ID

CPATR-13739

(Linux)

#### Description

Fixed an issue where the Cytool process failed, if other processes on the endpoint were executed with certain command lines.

#### Issue ID

CPATR-13558

(Linux)

#### Description

Optimized the Anti-Malware flow to reduce the number of actions performed by the Cortex XDR agent when scanning containerized applications, leading to lower latency and CPU usage.

#### Issue ID

CPATR-13542

(Windows)

#### Description

Fixed an issue where in rare cases, the Cortex XDR agent startup delayed the endpoint startup, leaving the endpoint partially protected during this time.

#### Issue ID

CPATR-13126

(Linux)

#### Description

Fixed an issue where IBM WebsShere failed to start after the Cortex XDR agent on the endpoint was upgraded to 7.3.0 or a later release.

#### Issue ID

CPATR-12448

(Windows)

#### Description

Fixed an issue where upgrading the Cortex XDR agent to a newer release failed if during the upgrade process, a 3rd party running on the endpoint was holding a handle to the agent service. For the fix to take effect, the upgrade must be performed from a fixed Cortex XDR agent 7.4.1 release or later.

### Addressed Issues in Cortex XDR Agent 7.4

The following table details addressed issues in Cortex XDR agent 7.4

#### Feature

CPATR-12633

(Windows)

#### Description

Fixed security issues.

#### Feature

CPATR-13408

(Windows)

#### Description

Fixed security issue.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/7.x/7.4-eol/addressed-issues-in-cortex-r-xdr-tm-agent-7.4.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
