Fixing and finding

[Jump to remediation plan](#remediation)

CVE ID

# CVE-2026-8398

Published 2026-05-15

Updated 3 months ago

Vendor/s

Daemon

Product/s

Daemon Tools Lite

Version/s

12.5.1

KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.

CVSS Score (v3.1)

9.8

/ 10

Critical

Severity Details

Base score

9.8 Critical

Attack vector

Network

Attack complexity

Low

Privileges required

None

User interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Table of Contents

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

## Description

Critical supply chain attack (CVSS 9.8) affecting DAEMON Tools Lite. Trojanized binaries bypass signatures. Active exploitation reported in CISA KEV.

## Why this matters

This CVE represents a severe supply chain compromise of DAEMON Tools Lite, carrying a critical CVSS score of 9.8. Because malicious code was embedded in official, digitally signed binaries—including DTHelper.exe and DiscSoftBusServiceLite.exe—it effectively bypasses traditional signature-based security controls. Its inclusion in the CISA KEV list confirms active exploitation. Organizations are at high risk of full system compromise if they installed the software between April and May 2026. The breach of the vendor's distribution infrastructure makes this a high-priority threat that requires immediate forensic investigation and remediation.

## CPE

Daemon

| Product       | Version Start | Version End (excl.) | Status     |
| ------------- | ------------- | ------------------- | ---------- |
| daemon\_tools | 12.5.1        | 12.5.1              | vulnerable |
| windows       | -             | -                   | unaffected |

## Related weakness (CWE)

CWE-506

## Remediation plan

1

### Apply official patches

Download the latest clean version of DAEMON Tools Lite directly from the official vendor website. Ensure you are using a version released after the May 2026 security incident and verify the installer's checksum against official vendor advisories.

2

### Update affected systems

Immediately uninstall compromised versions 12.5.0.2421 through 12.5.0.2434. While CPE data indicates version 12.5.1 may be affected, users should transition to the most recent version confirmed as clean by AVB Disc Soft to ensure all trojanized binaries are removed.

3

### Restrict access

Isolate any workstations running the affected software from the production network until they have been reimaged or verified clean. Block outbound network traffic from DAEMON Tools processes at the host or network firewall level to prevent potential command-and-control communication.

4

### Monitor for exploitation

Perform a retrospective hunt for the trojanized binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe) using known malicious hashes. Monitor for unusual child processes spawned by these services or unauthorized persistence mechanisms created during the period of infection.

## Detection Guidance

Detection should focus on identifying the specific trojanized binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. Since these files carry legitimate digital signatures, signature-based antivirus may fail. Security teams should use EDR tools to monitor for unusual outbound network connections or unexpected shell executions originating from these processes. Check system logs for installation events between April 8 and May 5, 2026, and audit for unauthorized registry modifications or scheduled tasks.

## References

[https://blog.daemon-tools.cc/post/security-incident Vendor Advisory ](https://blog.daemon-tools.cc/post/security-incident)[https://securelist.com/tr/daemon-tools-backdoor/119654/ Exploit Third Party Advisory ](https://securelist.com/tr/daemon-tools-backdoor/119654/)[https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field\_cve=CVE-2026-8398 US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-8398)

## Sources

NIST National Vulnerability Database (NVD)

CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](https://www.upguard.com/contact-sales)

[Free trial](https://www.upguard.com/demo)
