Vulnerabilities

CVE-2026-8398

Daemon Tools Lite Embedded Malicious Code Vulnerability

Actively exploited (CISA KEV) Critical 9.3 CVSS 4.0

Description

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.

Description as published by the source, in English.

Key facts

Published
2026-05-15
Last modified
2026-06-17
Assigned by
vulnerability@kaspersky.com
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Scored by
vulnerability@kaspersky.com
Probability of exploitation
1.5 % higher than 71 % of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15
Fix available
Not registered in the sources

Actively exploited

CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-05-27, with a remediation deadline of 2026-05-30 for US federal agencies.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected products

Vendor Product Versions Status
Disc-soft Daemon Tools 12.5.1 Affected
Microsoft Windows all versions listed Not affected

Weakness type

Attack techniques

Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.

  • T1001.002: Steganography command-and-control
  • T1027.003: Steganography stealth
  • T1027.004: Compile After Delivery stealth
  • T1027.009: Embedded Payloads stealth
  • T1195.001: Compromise Software Dependencies and Development Tools initial-access
  • T1195.002: Compromise Software Supply Chain initial-access
  • T1218.001: Compiled HTML File stealth
  • T1221: Template Injection stealth

References

Related at Berigo

Articles

Does this affect you?

A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.

Check your asset list Browse all vulnerabilities