SY0 701 > Zero-day vulnerabilities 2.3 > Flashcards
Vulnerabilities
Many applications have vulnerabilities. Have not found them yet.
Someone is working hard to find the next big vulnerability. The good guys share these with developers.
Attackers keep these yet to be discovered holes to themselves. They want to use these vulnerabilities for personal gain.
Zero-day attacks
Attackers search for unknown vulnerabilities. They create exploits against these vulnerabilities.
The vendor has no idea the vulnerability exists. They don’t have a fix for an unknown problem.
Zero-day attacks. An attack without a patch or method of mitigation. A race to exploit the vulnerability or create a patch. Difficult to defend against the unknown.
Zero-day attacks in the wild (see examples on slide).