CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

A software vendor releases a security advisory stating that attackers are actively exploiting a flaw in their product for which no patch currently exists. Which term best describes this vulnerability?

  1. AEnd-of-life vulnerability
  2. BZero-day vulnerability
  3. CMisconfiguration vulnerability
  4. DLegacy vulnerability
Show answer & explanation

Correct answer: B. Zero-day vulnerability

A zero-day vulnerability is one that is being actively exploited or is publicly known before the vendor has released a patch, giving defenders zero days to respond before exposure begins.

Why the other options are wrong

  • A. End-of-life refers to software no longer supported by the vendor, which is a different scenario.
  • C. Misconfiguration refers to improper settings, not a fundamental unpatched software flaw.
  • D. Legacy vulnerabilities relate to outdated but still supported systems, not necessarily unpatched flaws.

Zero-Day Vulnerability

A software flaw that is unknown to or unaddressed by the vendor, often exploited before a patch is available.

  • No official patch exists at time of exploitation
  • High risk due to lack of defenses
  • Often sold/traded on underground markets before disclosure

Memory trick: Zero-day means zero days of warning before it's used against you.

More Threats, Vulnerabilities, and Mitigations questions