Home AVB Disc Soft CVE-2026-8398
CRITICAL: THIS VULNERABILITY IS ACTIVELY BEING EXPLOITED IN THE WILD (CISA KEV CATALOG)
Back to AVB Disc Soft

CVE-2026-8398

Exploited

DAEMON Tools Lite - DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe

AVB Disc Soft CVSS 9.8 Updated May 29, 2026

Executive Risk Summary

"A supply chain attack compromised the official installation packages of DAEMON Tools Lite, allowing attackers to gain unauthorized access to the vendor's build or distribution infrastructure and trojanize three binaries. The malicious installers were digitally signed with the legitimate AVB Disc Soft code-signing certificate, making them appear trustworthy and bypassing signature-based detection."

Anticipated Attack Path

  1. 1. Initial Compromise: Attackers gain access to the vendor's build or distribution infrastructure
  2. 2. Exploitation: Trojanized binaries are digitally signed with the legitimate code-signing certificate
  3. 3. Post-Exploitation: Malicious code is executed on the compromised system

Am I Vulnerable?

  • Verify the digital signature of the DAEMON Tools Lite installation packages
  • Check for suspicious activity related to the compromised binaries
  • Update to a patched version of DAEMON Tools Lite

Operational Audit Arsenal

Target Type Windows Executable
Target Asset DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe
Standard Path C:\Program Files\DAEMON Tools Lite\

Manual Verification Required

This is a non-Windows asset (AVB Disc Soft). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Minimal to moderate disruption expected, depending on system configuration and usage

Internal Work Notes

Supply chain attack on DAEMON Tools Lite installation packages, resulting in compromised binaries and potential malicious code execution. Update to a patched version and verify digital signatures to mitigate the risk.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.