Skip to main content
Book 07 · SecurityPage 50 of 50

Zero-Day

Pronunciation
ZEER-oh day
Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/zero-day

In short

A zero-day is a software vulnerability that the vendor doesn't know about or hasn't fixed yet, so attackers can exploit it before any patch exists.

What is a zero-day vulnerability?

Most attacks use known vulnerabilities that already have patches. A zero-day is different: the flaw is discovered by attackers, or by researchers who sell it, before the vendor knows. A zero-day exploit is the code that takes advantage of it, and a zero-day attack is its use against real targets. Once the vendor releases a fix, the vulnerability is no longer a zero-day, though unpatched systems remain at risk.

Zero-days are valuable and therefore expensive. Exploits for widely used software such as browsers, phones and VPN appliances are bought by governments and criminal groups, and bug bounty programs pay researchers to report them to the vendor instead. Stuxnet, discovered in 2010, used four Windows zero-days to sabotage nuclear centrifuges, an early sign of their power.

By definition there is no patch to apply, so defense relies on limiting damage. Keeping attack surface small, isolating systems, running with least privilege, using memory-safe languages, monitoring for unusual behavior and being able to update very quickly once a fix appears all reduce the impact.

A common misconception is that zero-days are the main threat for most organizations. They make headlines, but far more breaches come from known vulnerabilities left unpatched for weeks or months, stolen passwords and phishing. Patching quickly is usually the most effective security measure.

Key takeaways

  • A zero-day is a vulnerability with no fix available yet.
  • Defenders have had zero days to prepare when it is first exploited.
  • Zero-day exploits are traded and are worth a lot of money.
  • Defense relies on least privilege, isolation and monitoring.
  • Most breaches still come from known, unpatched vulnerabilities.

Readers ask

Why is it called zero-day?

Because the vendor and defenders have had zero days to fix the problem since it became known, often because it is being exploited before the vendor even learns about it.

What is the difference between a zero-day and a CVE?

A CVE is a public identifier for a known vulnerability. A zero-day is a vulnerability that has no fix yet, often not even publicly known. Once disclosed, a zero-day usually gets a CVE number.

How do you protect against zero-day attacks?

You can't patch them in advance, so reduce exposure: minimize internet-facing services, apply least privilege, segment networks, use exploit protections and monitoring, and apply emergency fixes as soon as they are released.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings