What is a zero-day vulnerability?¶
A zero-day vulnerability is a flaw that was not publicly known, or had no available fix, at the relevant point in its disclosure or exploitation history. The label describes knowledge and remediation at a time; it does not prove a particular offender or level of sophistication.
It should not be used merely as a synonym for unpatched. A publicly known vulnerability whose update was not installed has a different status.
Establish the chronology¶
Record when the target activity occurred, when the flaw became known, and when a patch or mitigation became available. Identify the affected version and configuration and preserve the source and confidence of any vendor, government or specialist assessment.
Later public classification does not change what defenders could have known earlier. Reporting should explain that chronology rather than applying the current label without qualification.
Prove exploitation in the usual way¶
An unexplained crash or novel compromise does not itself establish a zero-day. Examine the request or code that reached the system, the vulnerable behaviour, resulting access and surviving records just as for any other exploitation claim.
Several actors may independently discover or obtain the same flaw, so zero-day use is not personal or group attribution. The classification may also change as analysis reveals an older disclosure, mitigation or different root cause.
Key takeaway
Use zero-day only when the knowledge-and-fix chronology supports it, and establish exploitation, effect and attribution from separate evidence.