Question

What is a zero-day vulnerability?

Vault Verified
Curated Intelligence
Definitive Source
Answer

A zero-day is a security flaw that the vendor does not yet know about, or has known about for zero days — so no patch exists and defenders have had no opportunity to prepare.

The related terms are used loosely but mean different things:

Zero-day vulnerability — the flaw itself, unknown to the vendor.

Zero-day exploit — working code that takes advantage of it.

Zero-day attack — the exploit used against real targets.

Why they are dangerous. Most security depends on knowing what to defend against. Signature-based detection looks for known threats; patching fixes known flaws. A zero-day defeats both by definition. Defence falls back on behavioural detection, sandboxing, least privilege and network segmentation — measures that limit damage rather than prevent entry.

Where they come from. Security researchers, criminal groups, and government agencies all find them. There is a substantial market: bug bounty programmes pay researchers to report flaws to the vendor, while exploit brokers pay considerably more to buy them for offensive use. Prices for reliable exploits against widely used platforms reach seven figures.

Responsible disclosure is the convention where a researcher reports privately and gives the vendor a fixed window — commonly 90 days, as with Google's Project Zero — before publishing. This balances giving time to fix against the risk that a flaw stays unpatched indefinitely.

The uncomfortable policy question. Government agencies discovering vulnerabilities face a choice between disclosing them so everyone can be protected, and retaining them for intelligence use. Retained vulnerabilities have leaked — EternalBlue, developed by the NSA, was leaked and used in the WannaCry and NotPetya attacks, causing billions in damage worldwide.

What you can actually do: patch immediately when fixes appear, since most real-world attacks use known vulnerabilities that were never patched; keep backups; enable automatic updates; and reduce attack surface by removing unused software.

Related Questions