CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2026-8398

CVSS 9.3v4.0pub. 2026-05-15upd. 2026-05-28

A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.

🤖 AI Analysis
How it works

Attackers gained unauthorized access to AVB Disc Soft's software build or distribution infrastructure and modified (trojaned) three binary files: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. The modified files were then signed with the vendor's legitimate code-signing certificate, causing security systems relying on digital signature verification to treat them as trusted. The compromised packages were distributed from the official daemon-tools.cc domain from approximately April 8, 2026 to May 5, 2026.

Impact

Users who installed compromised software versions could have been infected with malicious code with full privileges resulting from execution of the signed installer — attackers could gain a high level of control over the victim's system, including access to sensitive data and the ability to further compromise the environment.

Mitigation & patch

Immediately uninstall compromised versions (12.5.0.2421–12.5.0.2434) and install the version provided by the vendor after May 5, 2026 — according to information published on the vendor's blog (blog.daemon-tools.cc). Systems on which vulnerable versions were installed should be subjected to thorough security audits to detect any traces of compromise.

Who is affected

DAEMON Tools Lite for Windows versions 12.5.0.2421 to 12.5.0.2434, downloaded from the daemon-tools.cc domain from approximately April 8, 2026 to May 5, 2026

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Disc Soft Daemon Tools

    APP
    Disc-Soft
    12.5.1
  • Microsoft Windows

    OS
    Microsoft
    all versions

CISA KEV — detailsi

Vendori
Daemon
Producti
Daemon Tools Lite
Added to KEVi
May 27, 2026
Remediation deadline (US Federal)i
May 30, 2026(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 30 maja 2026
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2024-7262CRITICAL9.3⚠ KEVPL ✓same product

Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit

CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product

RCE przez YAML deserialization w IBM Aspera Faspex