Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a zero-day vulnerability?

A zero-day vulnerability is a flaw that was not publicly known, or had no available fix, at the relevant point in its disclosure or exploitation history. The label describes knowledge and remediation at a time; it does not prove a particular offender or level of sophistication.

It should not be used merely as a synonym for unpatched. A publicly known vulnerability whose update was not installed has a different status.

Incident timeWas the flaw unknown or without an available fix at the relevant event?
DisclosureWhen did the vendor or wider community first identify the flaw?
Mitigation / patchWhen did a practical fix or workaround become available?
Later classificationWhat was learned afterwards, and does that change how the earlier event should be described?

Establish the chronology

Record when the target activity occurred, when the flaw became known, and when a patch or mitigation became available. Identify the affected version and configuration and preserve the source and confidence of any vendor, government or specialist assessment.

Later public classification does not change what defenders could have known earlier. Reporting should explain that chronology rather than applying the current label without qualification.

Prove exploitation in the usual way

An unexplained crash or novel compromise does not itself establish a zero-day. Examine the request or code that reached the system, the vulnerable behaviour, resulting access and surviving records just as for any other exploitation claim.

Several actors may independently discover or obtain the same flaw, so zero-day use is not personal or group attribution. The classification may also change as analysis reveals an older disclosure, mitigation or different root cause.

Key takeaway

Use zero-day only when the knowledge-and-fix chronology supports it, and establish exploitation, effect and attribution from separate evidence.

Reference: CIM-096Cyber Incidents & Offender Methods