Zero-Day Vulnerability
A software or hardware flaw that is unknown to the vendor, or for which no fix is available, when attackers discover or exploit it, so defenders have had zero days to prepare a patch.
The name refers to the vendor having had zero days to address the flaw. A zero-day exploit is code or a technique that takes advantage of such a vulnerability, and a zero-day attack is its use against targets. Once a patch is released the vulnerability is no longer a zero-day, but systems that remain unpatched are still exposed, often more widely than before, because the published fix helps other attackers understand the flaw.
Zero-day exploits are valued by criminal groups, commercial spyware vendors and state-sponsored actors because signature-based defences cannot recognise them. Edge devices such as VPN gateways, firewalls and file-transfer appliances, along with browsers and mobile operating systems, have been frequent targets in publicly reported campaigns. Vendors and other organisations run vulnerability disclosure and bug bounty programmes so that researchers report flaws to them before attackers find them.
Because no patch exists at first, defence relies on reducing the attack surface, segmentation, least privilege, exploit mitigations built into operating systems, behaviour-based detection such as EDR, and rapid emergency patching once a fix appears. Threat intelligence and vendor advisories provide early warning, and an inventory of internet-facing assets shows where exposure lies. Coordinated vulnerability disclosure gives vendors time to fix flaws before details become public.
Key points
- Unknown to the vendor or unpatched when first exploited.
- Signature-based tools cannot detect exploits they have never seen.
- Behaviour-based detection and attack-surface reduction limit exposure.
- Coordinated disclosure gives vendors time to release fixes.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Vulnerability ManagementCybersecurity & Compliance
- Endpoint Detection and Response (EDR)Cybersecurity & Compliance
- Threat IntelligenceCybersecurity & Compliance
- Common Vulnerabilities and Exposures (CVE)Cybersecurity & Compliance
- Zero Trust Architecture (ZTA)Cybersecurity & Compliance