> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/7.x/7.5-eol/addressed-issues-in-cortex-r-xdr-tm-agent-7.5.md).

# Addressed Issues in Cortex® XDR™ Agent 7.5

* Addressed Issues in Cortex XDR Agent 7.5.3
* Addressed Issues in Cortex XDR Agent 7.5.2
* Addressed Issues in Cortex XDR Agent 7.5.1-hotfix
* Address Issues in Cortex XDR Agent 7.5.1
* Addressed Issues in Cortex XDR Agent 7.5.0-hotfix
* Addressed Issues in Cortex XDR Agent 7.5

### Addressed Issues in Cortex XDR Agent 7.5.3

The following has been addressed in this release:

* CPATR-16539: Fixed an issue addressing vulnerability CVE-2022-0778
* CPATR-15750: Fixed an issue where the web socket does not shut down properly after an agent shutdown.
* CPATR-16106: Fixed an issue where payload versions are not updated after an agent restart.
* CPATR-14814: Fixed an issue where the agent does not receive the WildFire verdict.
* CPATR-15441: Fixed an issue where the agent is using a large amount of disk space.
* CPATR-15591: Fixed an issue where the agent TMP folder fills up.
* CPATR-16354 (Windows): Fixed an issue where the agent does not appear in the Windows Security Center a reboot.
* CPATR-16387 (Windows): Fixed an issue where agents become unresponsive following an upgrade.
* CPATR-15310 (Windows): Fixed an issue where the agent fails to first query the hardware ID.
* CPATR-15041 (MacOS): Fixed an issue where uninstall of MacOS agent can fail due to the database structure.
* CPATR-15300 (Linux): Fixed an issue with log file folder permissions.

### Addressed Issues in Cortex XDR Agent 7.5.2

The following has been addressed in this release:

* CPATR-14804 (Windows): Fixed an issue where external USB drives scans are inconsistent with scan configuration.
* CPATR-14790 (MacOS): Fixed an issue where local analysis module preventions are reported with the wrong Incident ID on macOS Catalina impacting incident generation.
* CPATR-14788: Fixed an issue where agent proxy settings are incorrectly stored causing endpoints to become disconnected.
* CPATR-15252 (Windows), CPATR-14737: Fixed an issue where querying for hardware ID changes on an endpoint, NULL values are ignored.
* CPATR-14729(Windows): Fixed an issue where some processes may crash while the DLL Security module is enabled.
* CPATR-14717: Fixed an issue where the IP allow list may not always be applied correctly.
* CPATR-15228: Fixed an issue where agent crashes when deleting by hash more than the maximum configured number of file.
* CPATR-15252(Windows): Fixed an issue where when querying HWID changes, NULL value is ignored.
* CPATR-15252: Fixed an issue where an external USB drive is sometimes recognized as a fixed drive.
* CPATR-14737: Fixed an issue where querying for hardware ID changes on an endpoint, NULL values are ignored.
* CPATR-15228: Fixed an issue where hash deletion on a large number of files may cause the agent to halt.
* CPATR-15058: Fixed an issue where policy recalculation is triggered incorrectly.
* CPATR-15048: Fixed an issue where a prevention alert displays as Detected instead of Blocked.
* CPATR-14950: Fixed an issue where wildfire updates after an upgrade may cause a scan to halt.
* CPATR-14804 (Windows): Fixed an issue where external USB drives scans are inconsistent with scan configuration.
* CPATR-14790 (MacOS): Fixed an issue where local analysis module preventions are reported with the wrong Incident ID on macOS Catalina impacting incident generation.
* CPATR-14788: Fixed an issue where agent proxy settings may reset causing endpoints to become disconnected.
* CPATR-14729 (Windows): Fixed an issue where processes might crash while being enabled by DLL Security module.
* CPATR-14717: Fixed an issue where a blocked IP allow list may not always be applied correctly.

### Addressed Issues in Cortex XDR Agent 7.5.1-hotfix

The following has been addressed in this release for build numbers:

Windows - 7.5.1.40243 Mac - 7.5.1.2261 Linux - 7.5.1.39945

CPATR-14895: Fixed an issue where Cortex XDR agents running without trusting certificates “GlobalSign Root CA” may encounter issues downloading upgrade packages and content updates, and may also affect large scans verdict retrieval.

### Address Issues in Cortex XDR Agent 7.5.1

The following has been addressed in this release:

* CPATR-14801: Fixed an issue where updated WildFire verdict is not stored on the agent.
* CPATR-14726: Fixed an issue where a malware scan does not show the correct status when performing a reset.
* CPATR-14678: Fixed an issue where an agent might fail to cancel a scan if it has reached a time-out while the agent was not running (stopped).
* CPATR-14647: Fixed an issue where there was no message of successful upgrade to the current agent version.
* CPATR-14801: Fixed an issue where updated WildFire verdict was not stored on the agent.
* CPATR-14796: Fixed an issue where when an Adaptive Policy execution fails the agent my halt.
* CPATR-14726: Fixed an issue where a malware scan does not show the correct status when you perform a hard reset.
* CPATR-14725: Fixed an issue where a debugged process may halt.
* CPATR-14700: Fixed a compatibility issue in Citrix App Layering in which endpoints might fail to register.
* CPATR-14687: Fixed an issue where alerts, already categorized as exceptions, might be triggered.
* CPATR-14682: Fixed an issue where if a MacOS device reported partial properties, for example, missing serial number, rules enforcing that device were not enforced.
* CPATR-14647: Fixed an issue where there was no message of successful upgrade to current agent version.
* CPATR-14568: Fixed an issue where an unknown old WildFire verdict might not trigger a request for an expired verdict.
* CPATR-14560 (Windows Only): Fixed an issue where the Cortex XDR agent could lose connectivity to the server if the endpoint network location was changed frequently.
* CPATR-14430: Fixed an issue where Office macros might cause repeated uploads of the same file to WildFire if that file was successfully uploaded at least once by TUS.
* CPATR-14822: Fixed an issue where a scan on-demand continues to run when the endpoint is not connected.
* CPATR-14741: Fixed an issue where the Cortex XDR agent is disabled after installing it on MacOs.
* CPATR-14678: Fixed an issue where an agent might fail to cancel a scan if the scan action time-out is reached while the agent is not running (stopped).
* CPATR-14734: Fixed an issue where canceling an action after the agent reconnects may cause the agent to halt.

### Addressed Issues in Cortex XDR Agent 7.5.0-hotfix

The following has been addressed in this release:

CPATR-14585 (Windows): Fixed an issue on Windows endpoints where cloned processes could cause the endpoint to halt.The cloning mechanism is most common in Unix-based applications running the fork command, which is implemented by the Windows kernel cloning mechanism. However, in some cases, this issue could reproduce without Unix-based applications.

### Addressed Issues in Cortex XDR Agent 7.5

There are no addressed issues in this release.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/7.x/7.5-eol/addressed-issues-in-cortex-r-xdr-tm-agent-7.5.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
