Supported scenarios

The MCP Server for Vulnerability Remediation supports CVE patch discovery, vendor patch file discovery, and Fixlet generation for a defined set of update flows.

The MCP Server for Vulnerability Remediation supports the following scenarios.

CVE patch discovery

Given a CVE identifier, the server retrieves available patch information and can enrich the result with product and CPE data. A CVE may map to multiple products or KB articles. You must select and verify the intended product before you continue.

Microsoft patch file discovery

The server searches the Microsoft Update Catalog by KB article or catalog query and returns matching patch file metadata. Supported target architectures are x64, x86, and arm64.

Microsoft and BigFix compatibility fields use the vendor-published SHA-1 and SHA-256 algorithms. These values are file integrity metadata required by BigFix prefetch commands; they are separate from the SHA3-256 algorithm used for certificate pinning.

Google Chrome patch discovery

The server retrieves Google Chrome release and enterprise installer information for a requested channel and architecture. Evergreen download URLs are not version-pinned. Retain any warning returned with the metadata and consider it during review.

WinGet package discovery

The server retrieves installer metadata from WinGet manifests for a package identifier, version, and architecture. A WinGet manifest hash indicates that the file metadata was published in the manifest; it does not replace deployment testing.

Fixlet generation

The server selects an embedded template and generates BES XML for supported flows, including:

  • Windows cumulative updates.
  • Windows checkpoint and cumulative updates.
  • Microsoft KB executable updates.
  • .NET Framework cumulative updates.
  • MSI application updates.
  • EXE application updates.

Review behavior and vendor warnings before you import or deploy the content.

Unsupported scenarios

The current server does not:

  • Import generated Fixlets into a BigFix site.
  • Create, stop, retry, or delete BigFix actions.
  • Manage computers, operators, roles, sites, analyses, baselines, or tasks.
  • Automatically deploy generated content.
  • Replace product-owner validation of applicability or vendor authenticity.