Zero-Day Exploits - Attacks Before Patches Exist
About 2 min read
A zero-day attack is an attack that exploits a software vulnerability during the window between when the vulnerability is discovered and when a fix patch is released. The name comes from the fact that developers have "zero days" of lead time from becoming aware of the vulnerability to deploying countermeasures. Because no known signature exists, conventional security software struggles to detect it. In 2024, Google's Threat Analysis Group confirmed 97 zero-day vulnerability exploits in a single year, an increase over the previous year.
What Gets Decided While Waiting for a Fix
While no fix is available, the moves that can be taken run not in the direction of adding protection but in the direction of narrowing what can be used. Restricting the routes that reach it, halting the function, or limiting who may deal with it all cut into the intended use, so if the part cut away is needed for the work, the measure cannot be sustained for long. What is at issue when deciding an interim measure is therefore not its strength but how many days the restriction can be endured and, once it cannot, which part is restored first. Next, the moment of disclosure is a different moment from when use began. Disclosure marks when something became known; whether it was already in use before that cannot be read off from the disclosure. The order of the two can sometimes be established only by looking back afterwards at the records that remain. The work that starts upon disclosure therefore divides in two, preparing for what is coming and checking whether it had already come, and doing only the former leaves the latter undone. And a measure that stops things according to how they appear is no substitute for a fix, yet it is not wasted either. The useful life of such a clue is short, however: as long as there is room to produce the same result in a different appearance, what can be stopped is limited to the shape currently visible. Because the role of this measure is to secure time until the fix arrives, unless what will be advanced with that time is decided at the same moment, the measure stays in place and the actual fix is pushed back.
Zero-Day Attack Timeline
Historical Background
Zero-day attacks drew international attention in 2010 with Stuxnet. This malware, believed to have been developed by the United States and Israel, exploited four zero-day vulnerabilities to destroy the centrifuges at Iran's nuclear facility. It was the first publicly known case of a zero-day being used as a cyber weapon. In 2021, Log4Shell (the Log4j vulnerability) was exploited by attackers worldwide within hours of disclosure, demonstrating the urgency of applying patches. Zero-day vulnerabilities command high market value: an iOS remote code execution vulnerability is said to trade for millions of dollars on the broker market.
Characteristics of Zero-Day Attacks
Zero-day vulnerabilities are traded at high prices on the dark web and are also used in state-level cyberattacks. Even after discovering a vulnerability, attackers may keep it secret and exploit it covertly over a long period.
How to Think About Defense
A common misconception is that "zero-day attacks can't be prevented, so countermeasures are pointless." While complete prevention is difficult, defense in depth can keep damage to a minimum. By setting a unique, strong password for each service and enabling two-factor authentication, you can prevent account takeover even if a vulnerability is exploited. Enable automatic software updates and apply patches promptly once they are released.
Was this article helpful?