Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-8398

Published 2026-05-15
Updated 3 months ago
Vendor/s
Daemon
Product/s
Daemon Tools Lite
Version/s
12.5.1
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Critical supply chain attack (CVSS 9.8) affecting DAEMON Tools Lite. Trojanized binaries bypass signatures. Active exploitation reported in CISA KEV.

CPE

Daemon logo
Daemon
Product Version Start Version End (excl.) Status
daemon_tools 12.5.1 12.5.1 vulnerable
windows - - unaffected

Related weakness (CWE)

CWE-506

Remediation plan

1

Apply official patches

Download the latest clean version of DAEMON Tools Lite directly from the official vendor website. Ensure you are using a version released after the May 2026 security incident and verify the installer's checksum against official vendor advisories.

2

Update affected systems

Immediately uninstall compromised versions 12.5.0.2421 through 12.5.0.2434. While CPE data indicates version 12.5.1 may be affected, users should transition to the most recent version confirmed as clean by AVB Disc Soft to ensure all trojanized binaries are removed.

3

Restrict access

Isolate any workstations running the affected software from the production network until they have been reimaged or verified clean. Block outbound network traffic from DAEMON Tools processes at the host or network firewall level to prevent potential command-and-control communication.

4

Monitor for exploitation

Perform a retrospective hunt for the trojanized binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe) using known malicious hashes. Monitor for unusual child processes spawned by these services or unauthorized persistence mechanisms created during the period of infection.

Detection Guidance

Detection should focus on identifying the specific trojanized binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. Since these files carry legitimate digital signatures, signature-based antivirus may fail. Security teams should use EDR tools to monitor for unusual outbound network connections or unexpected shell executions originating from these processes. Check system logs for installation events between April 8 and May 5, 2026, and audit for unauthorized registry modifications or scheduled tasks.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management