SF-LABS-2026-02 / Vulnerability Disclosure
Brother Windows Software Local Privilege Escalation
Another clean path from an everyday user account to full SYSTEM control. This time in bundled Brother device software that is widely deployed across Windows fleets. The clip below shows a non-administrator obtaining a SYSTEM shell on the host. Brother has been notified and a coordinated fix is underway. The complete write-up and proof-of-concept follow once the 90-day embargo lapses.
Demonstration
Proof-of-Concept Video
The clip shows the escalation path end-to-end. A standard non-administrator user starts the exploit and the result is a SYSTEM-integrity shell running on the host. No administrator rights, no reboot, no user interaction beyond the initial exploit trigger.
Disclosure Record
Timeline and Affected Surface
Public Summary
What is Publicly Disclosed Now
SF-LABS-2026-02 is a local privilege escalation in bundled Brother device software that is widely deployed across Windows fleets. The exploit requires the attacker to already have code execution in a standard non-administrator user context on the target machine. That foothold is the routine outcome of phishing, drive-by download or commodity malware. SF-LABS-2026-02 converts any such standard-user foothold into SYSTEM on a fully patched endpoint running affected Brother software.
Defensive recommendations for the embargo period are limited to standard local-attack-surface hardening: enforce least-privilege user accounts, monitor SYSTEM-integrity process creation from user-context parents, audit installed Brother software components and consider removing optional bundled components that are not in active use. The affected-version matrix will publish when the disclosure window closes.
Sherlock Forensics will publish full technical detail (vulnerability class root cause, affected code paths, proof-of-concept, remediation guidance) when the disclosure window closes or earlier on vendor approval. Researchers and incident response teams who need pre-release notification under NDA can reach the lab at labs@sherlockforensics.com.
About
About Sherlock Forensics Labs
Sherlock Forensics Labs is the research arm of Sherlock Forensics, a Vancouver BC based digital forensics and cybersecurity practice. Lead researcher Ryan Purita is a Principal Security Consultant with 20 years of courtroom-tested digital forensics work plus CISSP, ISSAP and ISSMP certification. The lab follows industry-standard 90-day coordinated disclosure with vendor-acknowledged early-release provisions. See the Labs hub for active and archived disclosures.