CVE-2026-8398: Daemon Tools Lite Embedded Malicious Code Vulnerability
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
Other sources
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DAEMON Tools Liteto a version that resolves this vulnerability.Fixed in 12.6 - Upgrade
Upgrade
DAEMON Tools Liteto a version that resolves this vulnerability.Fixed in 12.6 or newer - Remove
Remove
DAEMON Tools Litefrom your environment.Uninstall the application if you suspect it may be infected (affected installers were in the 12.5.0.2421 through 12.5.0.2434 range).
- Compensating control
Run a full system scan using antivirus software with the latest version of the anti-virus databases after uninstalling the application.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8398?
CVE-2026-8398 is classified as a high-severity vulnerability due to the potential for unauthorized access through compromised software installation packages.
How do I fix CVE-2026-8398?
To fix CVE-2026-8398, users should uninstall the affected versions of DAEMON Tools Lite and download the latest version from the official website.
Who is affected by CVE-2026-8398?
CVE-2026-8398 affects users of DAEMON Tools Lite for Windows versions 12.5.0.2421 through 12.5.0.2434 that were downloaded during the specified timeframe.
What was compromised in CVE-2026-8398?
CVE-2026-8398 involved a supply chain attack that compromised the official installation packages of DAEMON Tools Lite.
When did the CVE-2026-8398 vulnerability occur?
The CVE-2026-8398 vulnerability was active between April 8, 2026, and May 5, 2026.