Vulnerability Description
A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between approximately April 8, 2026, and May 5, 2026. Attackers gained unauthorized access to the vendor's (AVB Disc Soft) build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. These files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing the malicious installers to appear trustworthy and bypass signature-based detection.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://blog.daemon-tools.cc/post/security-incident
- https://securelist.com/tr/daemon-tools-backdoor/119654/
FAQ
What is CVE-2026-8398?
CVE-2026-8398 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc be...
How severe is CVE-2026-8398?
CVE-2026-8398 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-8398?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.