Zero day
A zero day is a security vulnerability that is unknown to the software or hardware vendor and has not yet been patched.
A zero day is a security vulnerability that is unknown to the software or hardware vendor and has not yet been patched. The term is also used for the exploit or attack that takes advantage of such a flaw before defenders have a fix. Zero-day issues are especially dangerous because standard signature-based defences may not detect them initially.
Meaning and usage
In cybersecurity, zero day refers to a vulnerability that is not yet known to the vendor or has no available fix. The phrase is also used more broadly for the exploit or attack built around that vulnerability.
How zero-day attacks work
Attackers identify or purchase knowledge of an undisclosed flaw and use it before a patch exists. Because defenders have had no time to respond, the vulnerability can be exploited quietly until it is discovered and mitigated.
Why zero-day vulnerabilities matter
Zero-day flaws are considered high risk because they can be used for malware installation, unauthorized access, data theft, and other intrusions. They are difficult to block with traditional reactive defences before detection signatures or patches exist.
Defence and mitigation
Security teams typically rely on behaviour-based detection, network monitoring, application hardening, rapid patching once fixes are released, and layered controls rather than signatures alone. These measures reduce exposure but cannot eliminate the risk before discovery.
Key facts
- A zero-day vulnerability is a flaw unknown to the vendor or defenders at the time it is found or exploited.
- A zero-day exploit is the method or code used to take advantage of that flaw.
- A zero-day attack occurs when an attacker uses the exploit before a patch is available.
- Zero-day issues are especially dangerous because standard signature-based defences may not detect them initially.
- The term applies to vulnerabilities in software, hardware, and firmware.
Zero-day vulnerabilities affect Canadian individuals, businesses, government systems, and critical infrastructure, and Canadian cybersecurity guidance commonly treats them as high-priority threats requiring layered defences and rapid patching when fixes become available.
Frequently asked questions
What is a zero-day vulnerability?
What is a zero-day exploit?
What is a zero-day attack?
Why is it called a zero day?
Can zero-day flaws affect hardware as well as software?
References
- Wikipedia — https://en.wikipedia.org/wiki/Zero-day_vulnerabilitySupports: Basic definition of zero-day vulnerability, exploit, and attack
- RAND — https://www.rand.org/content/dam/rand/pubs/research_reports/RR1700/RR1751/RAND_RR1751.pdfSupports: Meaning of zero-day vulnerabilities and the term’s reference to days known to the vendor
- CrowdStrike — https://www.crowdstrike.com/en-us/cybersecurity-101/cyberattacks/zero-day-exploit/Supports: Distinction between vulnerability, exploit, and attack
- Splunk — https://www.splunk.com/en_us/blog/learn/zero-day.htmlSupports: Unknown vulnerabilities, lack of patches/signatures, and defence considerations
- SentinelOne — https://www.sentinelone.com/cybersecurity-101/threat-intelligence/zero-day-vulnerabilities-attacks/Supports: Attacks before patches and common impacts
- HPE — https://www.hpe.com/us/en/what-is/zero-day-vulnerability.htmlSupports: Definition of zero-day vulnerability and lack of patch
- Tenable — https://www.tenable.com/cybersecurity-guide/principles/zero-day-vulnerabilitySupports: Known vulnerability without a patch and the 'zero days' concept
- Orca Security — https://www.orca.security/glossary/zero-day-vulnerability/Supports: Zero-day applicability to software, hardware, and firmware