CVE-2026-8398
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
View on NVDAnalysis
A supply chain attack compromised official DAEMON Tools Lite installers (versions 12.5.0.2421 to 12.5.0.2434) between April and May 2026. Malicious binaries were signed with the legitimate vendor certificate to bypass detection. If you have used this utility recently, check for trojanized files like DTHelper.exe or DiscSoftBusServiceLite.exe.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCWE-506CISA KEV
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
EPSS
Technical description
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.