8 ms·
Is it really a "zero-day" if it's being used months later?
by milliams 3y ago
Is it really a "zero-day" if it's being used months later?
- wolfi1 3y agoit's a zero-day when it is not patched but still exploited
- dxd 3y agoI think it means that this exploit has been possible since the application was made, the zeroth day.
- efdee 3y agoIt doesn't. Technically, zero-day in the context of exploits means the exploit was circulating and/or being used before the authors of the attacked piece of software were made aware of the vulnerability (or before the vulnerability was made public, or before the day a patch was made available, depending on who you ask).
- arboles 3y agoI can stretch the definition of zero day to make a point. Zero day is a surprise exploit that gets used before it is discovered. WinRAR has not fixed this exploit, and since it's proprietary software we don't even know if the company is even aware or even cares. It's also alike a zero day in the other sense that protections against the exploit haven't been developed. While in a real zero day that's because not enough time has passed for volunteers to develop protections, the case here is proprietary software can't be modified by volunteers.
- deelowe 3y agoNot if the devs weren't aware. Zero day borrows it's terminology from contracts where zero day notice means that no prior notification is needed. A zero day exploit is one that's circulating in the wild prior to their having been a formal disclosure.
- deleted 3y ago[deleted]