A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
Attackers gained unauthorized access to AVB Disc Soft's software build or distribution infrastructure and modified (trojaned) three binary files: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. The modified files were then signed with the vendor's legitimate code-signing certificate, causing security systems relying on digital signature verification to treat them as trusted. The compromised packages were distributed from the official daemon-tools.cc domain from approximately April 8, 2026 to May 5, 2026.
Users who installed compromised software versions could have been infected with malicious code with full privileges resulting from execution of the signed installer — attackers could gain a high level of control over the victim's system, including access to sensitive data and the ability to further compromise the environment.
Immediately uninstall compromised versions (12.5.0.2421–12.5.0.2434) and install the version provided by the vendor after May 5, 2026 — according to information published on the vendor's blog (blog.daemon-tools.cc). Systems on which vulnerable versions were installed should be subjected to thorough security audits to detect any traces of compromise.
DAEMON Tools Lite for Windows versions 12.5.0.2421 to 12.5.0.2434, downloaded from the daemon-tools.cc domain from approximately April 8, 2026 to May 5, 2026
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDisc Soft Daemon Tools
APPDisc-Soft12.5.1Microsoft Windows
OSMicrosoftall versions
CISA KEV — detailsi
- Vendori
- Daemon
- Producti
- Daemon Tools Lite
- Added to KEVi
- May 27, 2026
- Remediation deadline (US Federal)i
- May 30, 2026(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.
Related vulnerabilities
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP
Path Traversal w Kingsoft WPS Office — ładowanie dowolnej biblioteki Windows
PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit
RCE przez YAML deserialization w IBM Aspera Faspex