SharePoint Business Data Connectivity Service Exploitation
An attacker has exploited the SharePoint Business Data Connectivity service by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting in remote code execution within the IIS worker process context.
Based on research by Rapid7 2026-09-28 9 steps · 3 queries T1190
Brief
Vulnerability
ContextaThe team published a new hunt based on the Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) (https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520). The analysis details an RCE vulnerability in the DbTypeReflector class within the Business Data Connectivity (BDC) service. Attackers use this flaw to instantiate malicious .NET gadget chains through the upload of specially crafted BDC model files.aa
HypothesisaThe adversary uploads a
Business Data Connectivity model file (.bdcm) containing a malicious .NET gadget chain, such as ObjectDataProvider, to achieve remote code execution within the context of the IIS worker process (w3wp.exe).aa
Scoping the
EstateaThe hunt begins by identifying vulnerable hosts through the hb_vulnerability_finding surface. The first query filters for servers currently flagged with CVE-2026-63520 or CVE-2026-55040 that do not have a suppressed status. This scoping step ensures the investigation focuses on SharePoint systems where the Business Data Connectivity service remains unpatched and susceptible to exploitation.aa
Monitoring Delivery and
ExecutionaThe hunt proceeds with a parallel search across network and process surfaces. One query monitors hb_http_activity for any requests involving the .bdcm file extension in either the URL path or query strings. These files transport the exploit payload. Since legitimate administrative updates to BDC models are infrequent, these requests provide a specific pivot point for investigating potential initial access attempts.aaSimultaneously, the hunt examines the hb_process_activity surface to identify rare child processes spawned by w3wp.exe. The SharePoint worker process typically maintains a predictable set of child processes related to health checks and internal tasks. This query baselines typical behavior and isolates instances where a shell, discovery tool, or unknown binary appears on three or fewer hosts. This helps identify the successful execution phase of the exploit chain.aa
Correlation and
TriageaAn automated triage agent evaluates the results from the scoping and search phases. The agent identifies hosts where a vulnerability finding, a BDC model upload, and a rare worker process child occur within a close temporal window. This correlation allows the hunt to settle on a verdict of exploitation by connecting the delivery of the exploit to its behavioral side effects. If the agent confirms these links, the hunt routes the host for immediate isolation.aa
Blind
SpotsaThis hunt cannot inspect encrypted HTTP traffic or the POST request bodies of BDC model uploads. Consequently, it cannot verify the specific .NET gadget chain within the XML file until the exploit triggers a process-level event. Additionally, the hunt misses failed exploit attempts if the environment does not ingest Microsoft SharePoint Unified Logging Service (ULS) logs, which would record internal class instantiation failures.aa
Beyond
DetectionaStandard detection rules often flag common web shell behavior but lack the context of the initial delivery vector. This hunt provides that context by identifying the specific Business Data Connectivity model traffic. By correlating the file delivery with the specific vulnerability status of the server, we reduce the false positive rate associated with general IIS process monitoring. If the hunt confirms a compromise, the practitioner should proceed to a forensic review of the recovered .bdcm files to validate the malicious .NET types used in the attack.
Steps
-
Detect BDC model traffic
Query · enrichmentFind HTTP requests involving .bdcm files which transport the exploit payload.
reads hb_http_activitysqlSELECT device_hostname, url_path, url_query, src_endpoint_ip, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%.bdcm%' OR LOWER(url_query) LIKE '%.bdcm%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. HTTP requests targeting BDC model paths. Silence means no .bdcm files were requested within the lookback period.
-
Find rare w3wp.exe children
Query · baselineDetect successful RCE by finding rare child processes spawned by the SharePoint IIS worker process.
reads hb_process_activitysqlSELECT LOWER(process_name) AS proc, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS total_runs, MIN(time) AS first_seen FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%w3wp.exe%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING host_count <= 3What a hit looks like. Anomalous child processes such as shells, discovery tools, or unexpected binaries on a small number of hosts. Benign activity includes standard SharePoint health scripts.
-
Triage exploitation evidence
Agent triageThe agent weighs the vulnerability status, file delivery evidence, and process behavior to identify hosts showing a complete exploit chain.
-
Route based on verdict
DecisionDirect the response to host isolation if exploitation is confirmed.
-
Isolate the impacted host
Response actionPrevent lateral movement and further command execution by isolating the compromised SharePoint server.
-
Forensic artifact review
Analyst taskAn analyst verifies the BDC model content to confirm the presence of malicious .NET gadget chains.
-
Verify remediation
Analyst taskEnsure the estate is protected against this RCE vulnerability after the hunt.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| SharePoint BDC Model Exploitation T1190 |
Yes | find-vulnerable-sharepoint, detect-bdcm-traffic, find-rare-iis-children |
| Arbitrary Command Execution via Gadget Chain T1106 |
Out of scope | Not examined by this hunt; belongs to a separate hunt. |
Blind spots
- Needs Decrypted HTTP traffic or POST request body inspection. Without inspecting the payload, the hunt cannot distinguish between a legitimate BDC model update and a malicious exploit file until execution occurs. It would answer What .NET types and gadget chains were actually contained within the BDC model XML?.
- Needs Microsoft SharePoint Unified Logging Service (ULS) logs. The hunt relies on the side effects of successful exploitation (process execution) and may miss failed attempts or more stealthy gadget chains that do not spawn processes. It would answer Whether the DbTypeReflector class logged an instantiation failure or the specific .NET type being resolved..
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | Target hostnames for the hunt; leave empty to scan the entire estate. |
vulnerability_ids | list[string] | CVE-2026-63520, CVE-2026-55040 | CVE identifiers associated with the SharePoint BDC vulnerability. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
| Web server / proxy logs | siem | network |
Source
---
analysis: A standard detection rule might flag w3wp.exe spawning cmd.exe, but this
hunt provides necessary context by identifying the delivery of Business Data Connectivity
(.bdcm) models and scoping the search to hosts with known unpatched RCE vulnerabilities,
reducing false positives from legitimate admin scripts.
blind_spots:
- id: encrypted-http-traffic
question: What .NET types and gadget chains were actually contained within the BDC
model XML?
requires: Decrypted HTTP traffic or POST request body inspection
risk: Without inspecting the payload, the hunt cannot distinguish between a legitimate
BDC model update and a malicious exploit file until execution occurs.
stage: initial-access-bdc-exploitation
- id: no-uls-logs
question: Whether the DbTypeReflector class logged an instantiation failure or the
specific .NET type being resolved.
requires: Microsoft SharePoint Unified Logging Service (ULS) logs
risk: The hunt relies on the side effects of successful exploitation (process execution)
and may miss failed attempts or more stealthy gadget chains that do not spawn
processes.
stage: initial-access-bdc-exploitation
coverage:
- stage: initial-access-bdc-exploitation
status: covered
steps:
- find-vulnerable-sharepoint
- detect-bdcm-traffic
- find-rare-iis-children
- reason: Not examined by this hunt; belongs to a separate hunt.
stage: execution-gadget-chain-command
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: keep-as-periodic-hunt
justification: Microsoft SharePoint servers often host sensitive corporate data;
an unauthenticated RCE represents a direct threat to the confidentiality and integrity
of that data within the internal network.
methodology: model-assisted
trigger: intel-report
hypothesis: An attacker has exploited the SharePoint Business Data Connectivity service
by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting
in remote code execution within the IIS worker process context.
labels:
- hunt
- attack.t1190
name: SharePoint Business Data Connectivity Service Exploitation
parameters:
lookback_days:
default: '14'
description: Days of history to examine.
type: number
scope_hosts:
default: []
description: Target hostnames for the hunt; leave empty to scan the entire estate.
type: list[host]
vulnerability_ids:
default:
- CVE-2026-63520
- CVE-2026-55040
description: CVE identifiers associated with the SharePoint BDC vulnerability.
from:
kind: article
observed: '2026-08-24'
ref: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520
type: list[string]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Scope the hunt to SharePoint Server Subscription Edition, SharePoint Server
2019, or 2016. Target systems where the Business Data Connectivity (BDC) service
is active.
references:
- name: 'Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)'
url: https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520
related:
- hunt: iis-w3wp-shell-execution
reason: Monitoring for shells spawned by w3wp.exe is a general behavioral hunt that
covers many web exploits but lacks the specific context of BDC model delivery.
relation: out-of-scope-alternative
scenario:
stages:
- name: SharePoint BDC Model Exploitation
observables:
- CVE-2026-63520
- CVE-2026-55040
- .bdcm model file upload
- LobSystem Type="Database"
- LobSystem Type="DotNetAssembly"
- TypeName="System.Windows.Data.ObjectDataProvider"
- TypeName="System.Diagnostics.Process"
- TypeName="System.Diagnostics.ProcessStartInfo"
slug: initial-access-bdc-exploitation
tactic: initial-access
techniques:
- T1190
- name: Arbitrary Command Execution via Gadget Chain
observables:
- Process.Start()
- System.Windows.Data.ObjectDataProvider
- System.Diagnostics.Process
- System.Diagnostics.ProcessStartInfo
- w3wp.exe spawning child processes
- SharePoint Site service account privileges
slug: execution-gadget-chain-command
tactic: execution
techniques:
- T1106
summary: Attackers exploit a remote code execution vulnerability in the Microsoft
SharePoint Business Data Connectivity (BDC) subsystem by uploading malicious .bdcm
model files. The exploit leverages an unrestricted .NET type instantiation flaw
in the DbTypeReflector class to execute arbitrary commands via an ObjectDataProvider
gadget chain under the context of the SharePoint service account.
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
web:
category: siem
name: Web server / proxy logs
telemetry:
- network
tlp: clear
type: investigation
---
# SharePoint Business Data Connectivity Service Exploitation
This hunt identifies exploitation of CVE-2026-63520, an RCE vulnerability in the SharePoint DbTypeReflector class. The attack involves the delivery of a Business Data Connectivity (BDC) model file (.bdcm) containing a .NET gadget chain like ObjectDataProvider. The hunt first scopes to hosts with known unpatched vulnerabilities, then concurrently searches for BDC model uploads and rare child processes spawned by the SharePoint worker process (w3wp.exe). An agent correlates the presence of the vulnerability, the file delivery, and anomalous process behavior to settle on a verdict.
## find-vulnerable-sharepoint
<!-- Identify vulnerable SharePoint hosts -->
Focus the hunt on hosts already flagged as vulnerable to the relevant SharePoint CVEs by scanning providers.
```sqlite target=endpoint role=scoping params=(vulnerability_ids=vulnerability_ids)
~~~yaml
expected: A list of resource IDs (hostnames) that have not yet been patched. Silence
indicates no known vulnerable hosts in the scanner's inventory.
reads:
- resource_uid
- cve_uid
- severity
- status
silence: not_evidence_of_absence
source: hb_vulnerability_finding
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT resource_uid, cve_uid, severity, status FROM hb_vulnerability_finding WHERE instr(',' || '{{vulnerability_ids}}' || ',', ',' || cve_uid || ',') > 0 AND status != 'suppressed'
```
## parallel-threat-search
<!-- Search for delivery and execution -->
parallel:
- → detect-bdcm-traffic
- → find-rare-iis-children
join: → triage-exploitation
## detect-bdcm-traffic
<!-- Detect BDC model traffic -->
Find HTTP requests involving .bdcm files which transport the exploit payload.
```sqlite target=web role=enrichment params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: HTTP requests targeting BDC model paths. Silence means no .bdcm files were
requested within the lookback period.
reads:
- device_hostname
- url_path
- url_query
- src_endpoint_ip
- time
silence: not_evidence_of_absence
source: hb_http_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, url_path, url_query, src_endpoint_ip, time FROM hb_http_activity WHERE (LOWER(url_path) LIKE '%.bdcm%' OR LOWER(url_query) LIKE '%.bdcm%') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## find-rare-iis-children
<!-- Find rare w3wp.exe children -->
Detect successful RCE by finding rare child processes spawned by the SharePoint IIS worker process.
```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: Anomalous child processes such as shells, discovery tools, or unexpected
binaries on a small number of hosts. Benign activity includes standard SharePoint
health scripts.
prevalence:
by: device_hostname
key:
- proc
rare_below: 4
reads:
- process_name
- device_hostname
- parent_process_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT LOWER(process_name) AS proc, COUNT(DISTINCT device_hostname) AS host_count, COUNT(*) AS total_runs, MIN(time) AS first_seen FROM hb_process_activity WHERE LOWER(parent_process_name) LIKE '%w3wp.exe%' AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY 1 HAVING host_count <= 3
```
## triage-exploitation
<!-- Triage exploitation evidence -->
```agent target=hunter
cite: required
context:
- find-vulnerable-sharepoint
- detect-bdcm-traffic
- find-rare-iis-children
max_iterations: 4
objective: Determine if any host has been exploited using CVE-2026-63520 or CVE-2026-55040
by correlating vulnerable status, BDC model uploads, and anomalous process execution.
success_criteria: A per-host verdict citing specific rows that demonstrate the exploit
chain.
tools:
- endpoint
- web
```
## decision-on-compromise
<!-- Route based on verdict -->
if~: "the triage verdict is malicious for at least one host based on correlated file and process evidence" (confidence: high, judge=hunter)
then: → isolate-impacted-host
indeterminate: → forensic-artifact-review
unavailable: → forensic-artifact-review (blind_spot: encrypted-http-traffic)
else: → verify-remediation
## isolate-impacted-host
<!-- Isolate the impacted host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the identified host and preserve memory for forensic investigation of the w3wp.exe process.
```
→ forensic-artifact-review
## forensic-artifact-review
<!-- Forensic artifact review -->
```manual target=analyst
Retrieve the .bdcm file mentioned in the HTTP traffic from the SharePoint server or database; check the XML content for TypeName attributes referencing ObjectDataProvider, DotNetAssembly, or other unusual .NET types.
```
→ verify-remediation
## verify-remediation
<!-- Verify remediation -->
```manual target=analyst
Verify that Microsoft SharePoint security updates from August 2026 or later are applied to all servers in the estate.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.