5 ms·
Yeah, it’s really confusing. Unless I don’t understand the term, it hasn’t been a zero day vulnerability for the past two years...
by biddlesby 6y ago
Yeah, it’s really confusing. Unless I don’t understand the term, it hasn’t been a zero day vulnerability for the past two years...
- PeterisP 6y agoThe days are counted from the release of a fix. If something been known for two years but a fix was released on 11th August, then it was a zero-day for the two years until 11th August and it's a "day-6" vulnerability today. IIRC the term was introduced to contrast with day-1 attacks with exploits developed by reverse engineering patches on the day they are released and attempting to exploit systems in the gap until they get patched.
- biddlesby 6y agoI see. Thank you for the explanation!