Log in Sign up
Back to Discover
💻

Zero-day vulnerability

technology Maturity 11-13 war conflict
This article covers sensitive topics: war_conflict. Parents can manage visibility in Parental Controls.

Computers sometimes have secret holes.

Vulnerability timeline.png
Vulnerability timeline.png
No one knows they are there. Even the people who made them do not know. Bad people can use these holes. They use them to get into things. We must fix them to stay safe. Can you keep your computer safe?
Comparing the average prices of different kinds of exploits, from 2015 until present.png
Comparing the average prices of different kinds of exploits, from 2015 until present.png

61 words

Computers sometimes have secret holes.

Vulnerability timeline.png
Vulnerability timeline.png

Even the makers of the computer do not know about them. These holes are called zero-days.

Bad people can find these holes. They use them to get into systems. They may try to steal data.

Comparing the average prices of different kinds of exploits, from 2015 until present.png
Comparing the average prices of different kinds of exploits, from 2015 until present.png

When a maker finds a hole, they make a fix. This fix is called a patch. A patch helps keep things safe.

It can take a long time to make a fix. Some people even buy and sell these secret holes. We must use patches to stay safe.

103 words

Computers are made of software and hardware. Most products have small mistakes called bugs. If a bug creates a security risk, it is a vulnerability.

Vulnerability timeline.png
Vulnerability timeline.png

A zero-day is a special kind of vulnerability. It is a secret hole in a system. The makers of the software do not know it exists. This means they have had zero days to fix it.

Bad actors can use these holes. They use a zero-day exploit to get inside a system. An exploit is a way to use the hole. They may use it to steal data or break things.

Comparing the average prices of different kinds of exploits, from 2015 until present.png
Comparing the average prices of different kinds of exploits, from 2015 until present.png

When a maker finds a hole, they make a patch. A patch is a fix that closes the hole. It can take weeks or months to make a patch. Some people buy and sell these secret holes. Governments are big buyers of zero-days. They may use them for their own work. Other people sell them to make money. To stay safe, users must install their patches quickly.

178 words

{ "text": "A zero-day vulnerability is a secret hole in a computer system. Most software has small mistakes called bugs. If a bug creates a security risk, it is called a vulnerability. A zero-day is a special kind of vulnerability that the makers do not know about yet. This means the creators have had zero days to fix the problem. Because the makers are unaware, they cannot protect their users from it.

Vulnerability timeline.png
Vulnerability timeline.png
These holes are very dangerous for many reasons. Some vulnerabilities might only cause a device to stop working. Others are much worse because they let an attacker run their own code. This can happen without the user ever knowing anything is wrong.
Comparing the average prices of different kinds of exploits, from 2015 until present.png
Comparing the average prices of different kinds of exploits, from 2015 until present.png
\n\nWhen someone uses a vulnerability, it is called an exploit. An exploit is the tool used to get inside a system. Attackers use exploits to steal data or install harmful software called malware. The process of dealing with these holes follows a specific path. First, a researcher finds the hole, which is called \"Day 0.\" Next, they report it to the software maker so a fix can be made. The maker then works to build a patch, which is a piece of code that closes the hole. This step can take many weeks or even many months to finish. Finally, the maker releases the patch to the public to fix the problem.\n\nHistory shows us how important these secret holes have become. In 2010, a computer worm named Stuxnet used four zero-days to damage a program in Iran. This event showed the world how much damage an exploit could do. After that, the market for these holes grew much larger. Many big companies like Google now have programs to find these flaws early. They want to fix them before criminals find them. This helps protect things like passwords and bank details.
Vulnerability timeline.png
Vulnerability timeline.png
\n\nThere is a huge market where people buy and sell these vulnerabilities. People are often divided into three groups: white, gray, and black. White market sellers give the holes to the makers to help fix them. Gray market buyers are often governments or intelligence agencies. The United States is one of the largest buyers in this group. Other big buyers include the United Kingdom, Canada, Australia, and New Zealand. Black market users are organized criminals who want to use the holes for crime. In 2015, the government and crime markets were much larger than the white market.
Comparing the average prices of different kinds of exploits, from 2015 until present.png
Comparing the average prices of different kinds of exploits, from 2015 until present.png
\n\nUnderstanding zero-days helps us see how we stay safe online. Even if a system is very secure, it can still be at risk

451 words

A zero-day vulnerability is a security hole in a computer system that is unknown to its developers. Because the creators are unaware of the flaw, they have had zero days to create a fix. This makes these vulnerabilities a severe threat to digital security. Most software and hardware contain bugs, which are mistakes in the code. When a bug creates a risk that someone can use to enter a system, it is called a vulnerability.

Vulnerability timeline.png
Vulnerability timeline.png

An exploit is the specific method or tool used to take advantage of a vulnerability. Attackers use exploits to penetrate a target's system for several purposes. They might disrupt operations, install malware, or exfiltrate data, which means stealing information. Some vulnerabilities only cause a denial of service, making a device stop working. The most dangerous exploits allow an attacker to inject and run their own code. This can happen without the user ever knowing the system has been compromised.

Researchers classify vulnerabilities into different stages based on their status. A vulnerability is considered "alive" if there is no public knowledge of it. It is considered "dead" once it has been disclosed but remains unpatched. If the software is no longer being maintained, these are called "immortal" vulnerabilities. There are also "zombie" vulnerabilities, which exist in older software versions but have been patched in newer ones.

Vulnerability timeline.png
Vulnerability timeline.png

Finding and fixing these flaws follows a specific timeline. The process begins at "Day 0" when a researcher identifies the vulnerability. Next, the researcher reports the finding to the vendor to start remediation. The vendor then undergoes patch development, which is the creation of a code fix. This stage can take weeks or even months depending on the complexity. Finally, the vendor reaches public disclosure by releasing the patch to users.

Vulnerability timeline.png
Vulnerability timeline.png

There is a massive global market for these exploits, divided into three main categories. The "white market" involves vendors or third parties like the Zero Day Initiative. Sellers in this market often receive a bug bounty, which is a reward for finding flaws. The "gray market" is the largest and most lucrative, consisting of government or intelligence agencies. The United States is a major buyer, alongside the "Five Eyes" nations: the United Kingdom, Canada, Australia, and New Zealand. Finally, the "black market" is used by organized crime for illegal activities.

Comparing the average prices of different kinds of exploits, from 2015 until present.png
Comparing the average prices of different kinds of exploits, from 2015 until present.png

Economics play a major role in how these vulnerabilities are used. In 2015, the government and crime markets were estimated to be ten times larger than the white market. Zero-day exploits can fetch millions of dollars, especially remote "zero-click" exploits. Research from the RAND Corporation shows that zero-day exploits remain usable for an average of 6.9 years. However, exploits purchased from third parties only remain usable for 1.4 years on average.

Comparing the average prices of different kinds of exploits, from 2015 until present.png
Comparing the average prices of different kinds of exploits, from 2015 until present.png

History shows how these tools can impact the real world. A famous example is the Stuxnet worm, which used four zero-day vulnerabilities in 2010. This worm was used to damage a nuclear program in Iran. This event showed the world the power of zero-day exploits and expanded the global market. Since then, many companies like Google have created programs to find these flaws early. By finding them first, they can prevent criminals from stealing passwords or bank details.

Because writing perfectly secure software is impossible, experts use various defense strategies. Many organizations use "defense-in-depth" tactics to protect their data. This means an attacker must breach multiple levels of security to succeed. Other methods include multi-factor authentication and air-gapping, which means disconnecting a computer from the internet. While detecting zero-day exploits is an active area of research, these layers help reduce the overall risk.

627 words
🖼️ Images & Media (2)
File:Vulnerability timeline.png
Vulnerability timeline.png
File:Comparing the average prices of different kinds of exploits, from 2015 until present.png
Comparing the average prices of different...
Up Next
💻
Vulnerability (computer security)
Technology
More to explore

What is Nepedia?

A free, ad-free encyclopedia for children. Every article is written at five reading levels, so the same page works for a five-year-old and a fifteen-year-old — use the level switcher above to see this one change. No account needed to read.