cytray.exe "bad image" errors following Agent update

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

cytray.exe "bad image" errors following Agent update

L2 Linker

Following the Cortex XDR Windows agent update to 8.3.0.49434 we started to see the following error affecting some application DLLs.

Clicking Ok makes the message go away and the application keeps working. TAC case was logged and an temporary Support Exception was added and applied to some affected hosts. This seemed to stop the error.

Wondering if anyone else is experiencing the same or similar issue? This affects approx. 2 DLLs on two separate applications of ours. I'd like to see a fix come in the form of an update to the Cortex XDR client, as applying a temporary support exception doesn't seem like a viable long term solution.

44 REPLIES 44

L2 Linker

@Jurriaan Indeed. I also checked just now. Surely it can't be much further off...and it better be fixed in the release.

L5 Sessionator

The thing only I know is that 8.4 is planning to be released on the week of April 15.

Even I don't know about 8.3.1, I guess it was planning to be released in late March and slide to behind in some reason.

L2 Linker

This is more likely not going to be addressed in any future releases of Cortex XDR agent, given the fact that it's considered a feature that's been recently added in 8.3.0 and not a bug. Going the exception route targeting only those affected systems seems to be the way to get around this issue. You can either contact the vendor of the affected application and see if their software has a way to add exceptions for Cortex .exe process, otherwise you need to create an exception and target those affected systems only. 

L2 Linker

Just logged in and notice agent version 8.4.0.51691 is out. I'm running some tests now and will report back.

@Jurriaan So far in my testing with 8.4.0 I am not seeing the error reoccur with Teamviewer.

For me, 8.4.0 is not available yet....

Where do you see 8.4.0 released?  I only know about creating the install inside the console and 8.4.0 isn't available, only 8.3.0.

Same here: in Cortex XDR Console only 8.3.0 available.

L1 Bithead

This morning I've received an email that maintenance release 8.3.1 will be available April 30th.
The release notes 8.3.1 state that the problem is addressed: "Fixed a compatibility issue with 3-party applications and Cytray.exe".

L1 Bithead

I just created Agent Installation for 8.3.1 and forced Update Agent on machines which had 8.2.1 installed. No more popups.

As far as I'm concerned my problem is solved. Unfortunately, it took almost took two months before Palo came with a working solution. Next time better....

@Jurriaan screengrab of available versions in our tenant. For us 8.4 definitely became available before 8.3.1...

cskoien_0-1714609327528.png

 

L3 Networker

Still do not have 8.4 in our tenant. 8.3.1 was released yesterday. Recommendations on holding the deployment of 8.3.1 in preparation for 8.4?

@CraigV123 I also don't have 8.4 available, but 8.3.1 did stop the popups at my site. So why holding on the deployment?

I was only thinking that from an agent EOL standpoint. I've been testing 8.3.1. and our IT department will be getting that rolled out within the week. Just wondered what people's opinions were.

 

I appreciate the feedback.

There are multiple ways to look at it. If the fixes in 8.3.1 are not relevant for your situation you could argue to hold off on spending time to roll it out. You could spend that time on preparing for 8.4.0, which will be available to all pretty soon I suppose.

Another way of seeing it is wanting to stay as close as possible to the next upcoming release. I think both are reasonable. It comes down to the time/people available to roll it out. Or maybe there is a policy in place that says to upgrade to the next available version as soon as possible.

There are probably more reasons to do one or the other.

It's not like 8.4.0 will be a completely overhauled version. It's just the next version of a continuous development.

  • 26777 Views
  • 44 replies
  • 3 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!