Creates firewall rules to block inbound web traffic and known malicious IPs associated with CVE-2022-47966 exploitation
This Automox Worklet™ creates Windows Firewall rules to protect endpoints from active exploitation of CVE-2022-47966, a critical vulnerability affecting various ManageEngine products. The Worklet blocks inbound traffic on ports 80 and 443, preventing web-based attacks against vulnerable services.
The Worklet also blocks all inbound and outbound communications with 15 IP addresses confirmed by CISA to have been used in attacks exploiting this vulnerability. This network-level isolation prevents both initial compromise and command-and-control communications if the endpoint is already compromised.
Important warnings: This Worklet will enable the Windows Firewall service if disabled. If no firewall profiles are enabled, it enables the Public profile. Blocking ports 80 and 443 inbound will make any web services hosted on the endpoint unavailable.
CVE-2022-47966 affects multiple ManageEngine products and allows unauthenticated remote code execution. APT actors have actively exploited this vulnerability against organizations running vulnerable ManageEngine installations.
CISA documented specific threat actor infrastructure used in these attacks. Blocking these IP addresses at the firewall level provides immediate protection while you work on patching affected applications.
This Worklet serves as emergency mitigation when patching cannot happen immediately. Use it alongside your patch management process to reduce risk during the remediation window.
Evaluation phase: The Worklet exits with code 0, always triggering remediation for manual execution. This Worklet is designed to run on-demand through FixNow or policy execution rather than scheduled compliance checks.
Remediation phase: The Worklet verifies the Windows Firewall service is running, starting it if necessary. It enables the Public firewall profile if no profiles are active. It then creates inbound block rules for TCP ports 80 and 443, plus inbound and outbound block rules for each known malicious IP address. Rules are named with [AUTOMOX WORKLET] prefix for identification.
Windows servers or workstations potentially running ManageEngine products
Windows Firewall service must be available (will be started automatically)
Administrative privileges to manage firewall rules
Understand impact: blocks all inbound web traffic on ports 80 and 443
Parameter: Revert (set to true to remove all firewall rules created by this Worklet)
After remediation, the Windows Firewall contains rules blocking inbound TCP traffic on ports 80 and 443, plus 30 additional rules blocking inbound and outbound traffic to known malicious IP addresses. You can view these rules in Windows Firewall with Advanced Security, identified by the [AUTOMOX WORKLET] prefix. You can verify this change through the Automox Activity Log or by checking the endpoint configuration directly.
Web services hosted on the protected endpoint become unavailable to external clients. After patching CVE-2022-47966, run this Worklet again with the Revert parameter set to true to remove the firewall rules and restore normal network operations.
Run this Worklet on a pilot Windows endpoint and review evaluation output for mitigate cve-2022-47966.
Confirm Automox activity logs show successful completion and exit code 0.
Verify endpoint state using checks aligned to evaluation script logic, such as the evaluation and remediation scripts.
Validate remediation effects from script operations such as Get-Service, Where-Object, Select-Object, then rerun evaluation for compliance.


By submitting this form you agree to our Master Services Agreement and Privacy Policy.
Already have an account? Log in
Consider Worklets your easy button
A Worklet is an automation script, written in Bash or PowerShell, designed for seamless execution on endpoints – at scale – within the Automox platform. Worklet automation scripts perform configuration, remediation, and the installation or removal of applications and settings across Windows, macOS, and Linux.

AUTOMOX + WORKLETS™
Uncover new possibilities with simple, powerful automation.
By submitting this form you agree to our Master Services Agreement and Privacy Policy