SF-LABS-2026-04 / PARTY LINE / Brother
Brother iPrint&Scan for Windows PARTY LINE Missing Authorization
Vendor report in preparationSherlock Forensics Labs identified a local privilege escalation weakness in Brother iPrint&Scan for Windows. A non-administrative local user can reach interfaces intended for trusted callers, with potential impact on service availability and stored configuration exposure. Vendor report is in preparation. Full technical write-up follows when the disclosure window closes.
SF-LABS-2026-01 / BIG BROTHER / Brother
Brother Windows Device Software BIG BROTHER Local Privilege Escalation
Reported, awaiting vendor acknowledgementA standard, non-administrator user can gain full SYSTEM control of a Windows machine running bundled Brother device software, with no admin rights and no user interaction. Reported to the vendor. Full technical write-up and proof-of-concept will be published here when the disclosure window closes.
SF-LABS-2026-02 / BLANK CHECK / Vendor under embargo
BLANK CHECK Local Privilege Escalation in a Major Windows Desktop Accounting Application
Reported, awaiting vendor acknowledgementA standard, non-administrator user can gain full SYSTEM control of any Windows machine running the affected application, with no admin rights, no reboot and no user interaction. Confirmed on the current, fully-updated release. Reported to the vendor through a coordinated channel. Full details and proof-of-concept withheld at the vendor's request.
SF-LABS-2026-03 / SILENT NIGHT / Vendor under embargo
SILENT NIGHT Local Privilege Escalation in a Major Windows Desktop Accounting Application
Reported, awaiting vendor acknowledgementA second, distinct SYSTEM-level flaw in the same application. A standard, non-administrator user can gain full SYSTEM control in a single step on a fully-updated install, with no admin rights and no reboot. Reported to the vendor through a coordinated channel. Full root-cause analysis and proof-of-concept withheld at the vendor's request.