SF-LABS-2026-03 / SILENT NIGHT / Vulnerability Disclosure
Intuit QuickBooks Desktop SILENT NIGHT Local Privilege Escalation
All is calm, all is quiet... and then a standard user quietly wakes up as SYSTEM.
A second, distinct SYSTEM-level flaw in QuickBooks Desktop. A standard, non-administrator user can gain full SYSTEM control in a single step on a fully-updated install, with no admin rights and no reboot. Reported to Intuit. Full root-cause analysis and proof-of-concept follow once the disclosure window closes.
Demonstration
Proof-of-Concept Video
Video proof-of-concept will be added when available. The recording shows the escalation path end-to-end, from the unprivileged-user starting state to the SYSTEM shell that results.
Disclosure Record
Timeline and Affected Surface
Public Summary
What is Publicly Disclosed Now
SF-LABS-2026-03 SILENT NIGHT is the second distinct local privilege escalation finding in Intuit QuickBooks Desktop disclosed by Sherlock Forensics Labs. The first finding (SF-LABS-2026-02 BLANK CHECK) targets a separate component of the QuickBooks Desktop product. SILENT NIGHT operates on a different code path. Both findings reach SYSTEM from a standard non-administrator user context on a fully patched Windows host running QuickBooks Desktop 2024 current release.
The exploit requires the attacker to already have code execution in a standard non-administrator user context on the target machine. That foothold is the routine outcome of phishing, drive-by download or commodity malware. SILENT NIGHT converts any such standard-user foothold into SYSTEM with no user interaction and no reboot. The escalation requires no user interaction and no reboot.
Defensive recommendations for the embargo period are limited to standard local-attack-surface hardening: enforce least-privilege user accounts, restrict execution of unsigned or untrusted binaries from user-writable locations and review installed-software inventory against the public affected-versions list once it lands.
Sherlock Forensics will publish full technical detail when the disclosure window closes or earlier on vendor approval. Researchers and incident response teams who need pre-release notification under NDA can reach the lab at labs@sherlockforensics.com.
About
About Sherlock Forensics Labs
Sherlock Forensics Labs is the research arm of Sherlock Forensics, a Vancouver BC based digital forensics and cybersecurity practice. Lead researcher Ryan Purita is a Principal Security Consultant with 20 years of courtroom-tested digital forensics work plus CISSP, ISSAP and ISSMP certification. The lab follows industry-standard 90-day coordinated disclosure with vendor-acknowledged early-release provisions. See the Labs hub for active and archived disclosures.