Zero-Day
- Pronunciation
- ZEER-oh day
In short
A zero-day is a software vulnerability that the vendor doesn't know about or hasn't fixed yet, so attackers can exploit it before any patch exists.
What is a zero-day vulnerability?
Most attacks use known vulnerabilities that already have patches. A zero-day is different: the flaw is discovered by attackers, or by researchers who sell it, before the vendor knows. A zero-day exploit is the code that takes advantage of it, and a zero-day attack is its use against real targets. Once the vendor releases a fix, the vulnerability is no longer a zero-day, though unpatched systems remain at risk.
Zero-days are valuable and therefore expensive. Exploits for widely used software such as browsers, phones and VPN appliances are bought by governments and criminal groups, and bug bounty programs pay researchers to report them to the vendor instead. Stuxnet, discovered in 2010, used four Windows zero-days to sabotage nuclear centrifuges, an early sign of their power.
By definition there is no patch to apply, so defense relies on limiting damage. Keeping attack surface small, isolating systems, running with least privilege, using memory-safe languages, monitoring for unusual behavior and being able to update very quickly once a fix appears all reduce the impact.
A common misconception is that zero-days are the main threat for most organizations. They make headlines, but far more breaches come from known vulnerabilities left unpatched for weeks or months, stolen passwords and phishing. Patching quickly is usually the most effective security measure.
Key takeaways
- A zero-day is a vulnerability with no fix available yet.
- Defenders have had zero days to prepare when it is first exploited.
- Zero-day exploits are traded and are worth a lot of money.
- Defense relies on least privilege, isolation and monitoring.
- Most breaches still come from known, unpatched vulnerabilities.
Readers ask
Why is it called zero-day?
Because the vendor and defenders have had zero days to fix the problem since it became known, often because it is being exploited before the vendor even learns about it.
What is the difference between a zero-day and a CVE?
A CVE is a public identifier for a known vulnerability. A zero-day is a vulnerability that has no fix yet, often not even publicly known. Once disclosed, a zero-day usually gets a CVE number.
How do you protect against zero-day attacks?
You can't patch them in advance, so reduce exposure: minimize internet-facing services, apply least privilege, segment networks, use exploit protections and monitoring, and apply emergency fixes as soon as they are released.
See also
- CVESecurity, p. 9A CVE is a unique public identifier, such as CVE-2021-44228, given to one known security vulnerability so everyone can refer to the same flaw by one name.
- MalwareSecurity, p. 20Malware (malicious software) is any program designed to harm a computer or its user by stealing data, spying, damaging files or taking control of the system.
- Penetration TestingSecurity, p. 26Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
- Principle of Least PrivilegeSecurity, p. 28The principle of least privilege is a security rule that every user, program, and service gets only the minimum access it needs to do its job, and no more.
- Supply Chain AttackSecurity, p. 43A supply chain attack compromises software through something it relies on, like an open-source package, a build tool or an update server, not the app itself.
- OWASP Top 10Security, p. 24The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
Spotted a mistake or something missing on this page?Suggest an edit