What is a zero-day vulnerability?

A zero-day vulnerability is a security flaw for which no fix is yet available at the time it poses a threat. It may, for example, still be unknown to the software vendor when it is discovered or exploited by cybercriminals.


The term “zero-day” refers to the fact that the vendor effectively has zero days’ warning to fix the vulnerability once it starts being exploited.

This situation is particularly problematic. When a conventional vulnerability is known and a security patch is available, companies can update their systems to protect themselves. With a zero-day vulnerability, that protection is not yet available.

An open door for cybercriminals

A cybercriminal with an exploit capable of taking advantage of the vulnerability may then attempt to gain access to systems, steal information, install malware or obtain additional privileges before the vendor provides a solution.

When a zero-day vulnerability is discovered, cybersecurity researchers and the vendor concerned generally work to analyse it and develop a fix. Once a patch becomes available, it is important for companies to install it quickly.

Cybersecurity: The 6 Most Common Mistakes Companies Make

In the meantime, other security measures can help reduce the risk, including monitoring for suspicious behaviour, EDR/XDR solutions, network segmentation, access controls and temporary mitigation measures recommended by the vendor.

Zero-day vulnerabilities demonstrate why cybersecurity cannot rely on updates alone: a company must also be able to detect and respond to threats it does not yet know about.

...

Tell us about your cybersecurity needs

Thank you for your message, we’ll contact you very soon! Fill all fields Error when creating request. Please try again
6Lcp1CAbAAAAAM-4iEYkG33vfIaUYODi6YEXTTqi