Research

Sherlock Forensics Labs: Responsible Disclosure Tracker

Live status on coordinated security disclosures led by our research team. We follow industry-standard 90-day coordinated disclosure with vendor-acknowledged early-release provisions. Active findings are listed with a public summary plus countdown to the disclosure window close once the vendor acknowledges. Full technical detail publishes on schedule or earlier when the vendor confirms a fix.

In Disclosure Window

Active Disclosures

SF-LABS-2026-04 / PARTY LINE / Brother

Infographic depicting SF-LABS-2026-04 PARTY LINE vulnerability in Brother iPrint&Scan for Windows: local privilege escalation with potential impact on service availability and stored configuration exposure. Vendor report in preparation.

Brother iPrint&Scan for Windows PARTY LINE Missing Authorization

Vendor report in preparation

Sherlock Forensics Labs identified a local privilege escalation weakness in Brother iPrint&Scan for Windows. A non-administrative local user can reach interfaces intended for trusted callers, with potential impact on service availability and stored configuration exposure. Vendor report is in preparation. Full technical write-up follows when the disclosure window closes.

SF-LABS-2026-01 / BIG BROTHER / Brother

Infographic depicting SF-LABS-2026-01 BIG BROTHER vulnerability: standard user without admin rights gains full SYSTEM control via Brother bundled Windows device software. No user interaction required. Vendor notified.

Brother Windows Device Software BIG BROTHER Local Privilege Escalation

Reported, awaiting vendor acknowledgement

A standard, non-administrator user can gain full SYSTEM control of a Windows machine running bundled Brother device software, with no admin rights and no user interaction. Reported to the vendor. Full technical write-up and proof-of-concept will be published here when the disclosure window closes.

SF-LABS-2026-02 / BLANK CHECK / Vendor under embargo

Infographic depicting SF-LABS-2026-02 BLANK CHECK vulnerability: unprivileged local-to-system escalation in an undisclosed major Windows desktop accounting application. Standard user gains full SYSTEM control with no reboot and no user interaction. Vendor under embargo.

BLANK CHECK Local Privilege Escalation in a Major Windows Desktop Accounting Application

Reported, awaiting vendor acknowledgement

A standard, non-administrator user can gain full SYSTEM control of any Windows machine running the affected application, with no admin rights, no reboot and no user interaction. Confirmed on the current, fully-updated release. Reported to the vendor through a coordinated channel. Full details and proof-of-concept withheld at the vendor's request.

SF-LABS-2026-03 / SILENT NIGHT / Vendor under embargo

Infographic depicting SF-LABS-2026-03 SILENT NIGHT vulnerability: single-step privilege escalation in an undisclosed major Windows desktop accounting application. One action grants standard user instant SYSTEM control with no reboot and no user interaction. Vendor under embargo.

SILENT NIGHT Local Privilege Escalation in a Major Windows Desktop Accounting Application

Reported, awaiting vendor acknowledgement

A second, distinct SYSTEM-level flaw in the same application. A standard, non-administrator user can gain full SYSTEM control in a single step on a fully-updated install, with no admin rights and no reboot. Reported to the vendor through a coordinated channel. Full root-cause analysis and proof-of-concept withheld at the vendor's request.

Fully Released

Disclosed Archive

No publicly released advisories yet. Released disclosures with full technical detail will appear here once the disclosure window closes on each finding.

How We Work

Lab Methodology and Disclosure Policy

Sherlock Forensics Labs operates on the 90-day coordinated disclosure model. When our research surfaces a vulnerability in a vendor product, we notify the vendor on day zero with full technical detail. The vendor has 90 days from acknowledgement to ship a fix before public disclosure. If the vendor confirms a fix earlier we publish at vendor approval. If 90 days elapse without a fix we publish on schedule.

Our public stance during the disclosure window is minimal. We acknowledge the existence of the finding, the vendor and product affected, the high-level vulnerability class and a status indicator on the disclosure timeline. We do not publish proof-of-concept code, exploitation specifics or technical details that would enable an attacker before affected users have remediation available.

Researchers and incident response teams who need pre-release notification under NDA can reach the lab at labs@sherlockforensics.com. Coordinated-disclosure peer review by other vendor security teams is welcomed.

About the Researcher

Ryan Purita

Ryan Purita is the Principal Security Consultant at Sherlock Forensics and the lead researcher for Sherlock Forensics Labs. Ryan holds CISSP, ISSAP and ISSMP certifications and has 20 years of digital forensics and security research experience. His prior work includes courtroom-tested forensic examination for civil and criminal proceedings, security advisory engagements for legal and enterprise clients across North America and original vulnerability research published through the Sherlock Forensics platform.

Lab disclosures are reviewed by the Sherlock Forensics technical team before vendor notification and again before public release. See the broader Sherlock Forensics About page for the research team background.

Forensic Posture

Beyond the Lab: Forensic Tools for IR Teams

The Sherlock Forensics tool suite ships the artifact-extraction layer that IR teams reason over during compromise investigations. Sherlock Forensics Disk Imager for forensic acquisition. Sherlock Forensics PST Viewer for mailbox forensics. Sherlock Forensics Universal Events Viewer for Windows event log triage. For court-defensible engagements contact our team for expert witness services.

Since 2006CISSP, ISSAP, ISSMP certified888.883.4550