Vulnerabilities
2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-8398 | Trojanized Installer Backdoor in DAEMON Tools Lite (Supply Chain Compromise) CVE-2026-8398 (CWE-506, embedded malicious code) is a supply chain compromise in which attackers gained access to AVB Disc Soft's build or distribution infrastructure and trojanized the official Windows installers of DAEMON Tools Lite versions 12.5.0.2421 through 12.5.0.2434, distributed from the legitimate site daemon-tools.cc between approximately April 8 and May 5, 2026. The flaw is triggered by installing or running one of these tampered builds, which shipped backdoored copies of DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe digitally signed with the vendor's legitimate code-signing certificate, allowing them to bypass signature-based detection. Once executed, the embedded backdoor gives attackers a trusted foothold and code execution on the affected Windows host, potentially enabling credential theft, further compromise, or ransomware follow-on activity (ransomware linkage currently unknown). Anyone who downloaded and installed DAEMON Tools Lite from the official site during the affected window is impacted; users with other or older builds are not part of this trojanized distribution. The issue was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-27, confirming exploitation in the wild, and a public technical write-up is available via Kaspersky's Securelist. Do: Identify hosts that installed DAEMON Tools Lite 12.5.0.2421–12.5.0.2434 from daemon-tools.cc during the affected window; remove/reinstall the software from a clean, current build obtained from the vendor and verify the signatures of DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. Because the trojanized binaries were validly signed, treat affected systems as potentially compromised and hunt for persistence, anomalous process activity, and C2 traffic associated with the backdoor. Federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product by the KEV deadline (listed 2026-05-27). | 9.3 | 1% | KEV PoC |
| largeplausibly ~100,000–1,000,000 Windows installs of the affected builds during the ~4-week trojanized distribution window | |
| CVE-2021-21832 | A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. A specially crafted malformed file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — |