Impact
x64dbg-MCP Server, a native Model Context Protocol plugin for x64dbg, exposes the full debugger functionality over HTTP and server-sent events. In versions prior to 1.1 the service listens on all network interfaces by default and does not require authentication. Any network client that can reach the listening ports (9094 for the 64‑bit build and 9095 for the 32‑bit build) can execute arbitrary debugger commands, attach to processes by PID, read or write debuggee memory, and write files to arbitrary paths. This allows an attacker to run arbitrary code with the privileges of the x64dbg process, effectively granting remote code execution. The weakness is identified as CWE‑306 (Missing Authentication for Critical Function).
Affected Systems
The affected product is the x64dbg-MCP Server plugin developed by duty1g. Versions before 1.1 expose the vulnerability; any deployment using 1.0 or older is affected. The service is bound to 0.0.0.0 by default unless explicitly configured otherwise.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is rated critical. The EPSS score is not available, but the lack of authentication and open network binding make exploitation straightforward for anyone who can reach the service. The vulnerability is not listed in CISA’s KEV catalog, but its high severity and ease of exploitation mean it should be treated with the highest priority. Attackers can launch the vulnerability remotely over the network without any special privileges on the host system.
OpenCVE Enrichment