Zero Day

Zero-Day Vulnerability / Exploit

Zero-Day-Schwachstelle

A zero-day vulnerability is a security flaw still unknown to the defenders (or the manufacturer) and for which there is therefore no patch yet. The name stems from the fact that the manufacturer had „zero days“ to fix it before it was exploited. It is especially dangerous because classic defence is oriented towards the known.

History & facts. As long as a vulnerability is undiscovered or unpublished, there is neither signature nor patch — it can be exploited unnoticed (a „zero-day exploit“). Such flaws are a valuable commodity: they are traded, hoarded by specialised actors and deployed in a targeted manner in high-value attacks (Stuxnet, for instance, used several at once). After discovery a race begins: the manufacturer develops a patch, attackers try to exploit the flaw before its widespread application — the phase in which the zero-day becomes an „N-day“. Outlook & recommendation. No patch helps against true zero-days — but defence in depth does: segmentation, least privilege, behaviour-based detection and good visibility to recognise the exploitation by its consequences, not by a signature. At least equally important is discipline with the many known flaws: most successful attacks use not zero-days but long-patched vulnerabilities. Therefore: close known, actively exploited flaws (see KEV) in a prioritised manner and work with exploit probabilities (see EPSS).
Zero Day — Zero-Day Vulnerability / Exploit