Zero-Day
A software vulnerability that is unknown to the vendor and has no available patch, leaving no time (zero days) to prepare a defense before it is exploited.
Definition
A zero-day vulnerability is a previously unknown flaw in software or hardware that the vendor has not yet discovered or patched, meaning defenders have had zero days to prepare before it can be exploited. A zero-day exploit is the method attackers use to take advantage of that flaw, often before any detection signature or fix exists.
Zero-day vulnerabilities are discovered either by security researchers who responsibly report them to the vendor, or by attackers and specialized brokers who keep them secret to sell or use for their own purposes. Once an attacker has a working exploit, they can use it against targets with minimal risk of detection, since no antivirus signature or patch yet exists to stop it. Some zero-days are used in narrow, highly targeted attacks against specific high value organizations, while others are eventually incorporated into widely available exploit kits once their existence becomes known.
Zero-days matter because they remove the usual advantage of good patch hygiene, an organization can be fully up to date and still be exploited through a flaw nobody yet knows exists. They are particularly concerning when found in widely used software such as operating systems, browsers, or VPN appliances, since a single zero-day can potentially affect thousands of organizations simultaneously, including critical infrastructure and financial institutions in Indonesia. The period between discovery and a vendor releasing a patch, and the further period until organizations actually apply that patch, represents the highest risk window.
Because zero-days by definition cannot be patched in advance, defense relies on layered controls: network segmentation to limit lateral movement, behavior-based detection tools that flag unusual activity rather than known malware signatures, and rapid patch deployment processes once a fix is released. Reducing the attack surface, by disabling unnecessary services and restricting internet-facing systems, limits the number of ways a zero-day exploit can reach critical systems. Monitoring vendor security advisories and threat intelligence feeds helps organizations respond quickly once a zero-day becomes public.
At a glance
- Type
- Vulnerability category
- Primary targets
- Widely used software and hardware
How it works
- 1
Discovery: a flaw is found either by researchers who report it responsibly or by attackers who keep it secret.
- 2
Exploit development: attackers build a working method to take advantage of the flaw before any fix exists.
- 3
Use in the wild: the exploit is used against targets with minimal detection risk, since no signature or patch exists yet.
- 4
Disclosure: the vendor eventually learns of the flaw and begins developing a patch.
- 5
Patch window: the period between disclosure and organizations actually applying the fix is the highest-risk window.
Key points
- A zero-day is a flaw the vendor has not yet discovered or patched
- Good patch hygiene alone cannot stop an exploit for a flaw nobody yet knows exists
- A single zero-day in widely used software can affect thousands of organizations at once
- Some zero-days are used narrowly against high-value targets before becoming widely known
- Defense relies on layered controls since zero-days cannot be patched in advance
Best practices
- Apply network segmentation to limit lateral movement if a zero-day is exploited
- Use behavior-based detection that flags unusual activity rather than known signatures
- Reduce attack surface by disabling unnecessary services and internet-facing systems
- Deploy vendor patches rapidly once a fix for a disclosed zero-day is released
- Monitor vendor security advisories and threat intelligence feeds for early warning
Real-world example
A VPN appliance used by several Indonesian financial institutions has an undisclosed flaw that attackers have been quietly exploiting for weeks. Once a security researcher discovers and reports it, the vendor rushes out a patch, and organizations that deployed it within days avoid the wave of attacks that hit slower adopters.
How Claro helps
While Claro does not patch software vulnerabilities, its incident response and awareness content helps organizations prepare employees to recognize and report suspicious activity that may indicate a zero-day exploit is already in use.
Frequently asked questions
Why is it called a zero-day?
Because defenders have had zero days to prepare a fix before the flaw can be exploited, since the vendor was not yet aware of it.
Can a fully patched organization still be exploited?
Yes. A zero-day exploits a flaw nobody yet knows exists, so being up to date on known patches does not protect against it.
How do organizations defend against something that cannot be patched in advance?
Through layered controls such as network segmentation, behavior-based detection, and a reduced attack surface, combined with rapid patch deployment once a fix becomes available.
Who typically discovers zero-day vulnerabilities?
Security researchers who responsibly disclose them to the vendor, or attackers and specialized brokers who keep them secret to sell or exploit.
Related terms
Malware
Any software intentionally designed to damage, disrupt, or gain unauthorized access to a device or network.
Watering Hole Attack
An attack that compromises a legitimate website frequently visited by a target group, infecting visitors instead of attacking them directly.
Incident Response
The structured process an organization follows to detect, contain, investigate, and recover from a security incident.
Ransomware
Malware that encrypts an organisation's files or locks its systems, then demands a payment to restore access.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo